Segmentation Fault in Linux Kernel's IPv6 Decapsulation Mechanism
CVE-2026-80840

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80840?

A buffer overflow vulnerability exists in the Linux kernel due to improper handling of IPv6 control blocks during IPIP decapsulation. When an IPv4 packet is encapsulated within IPv6 segments, the inner packet can unintentionally utilize stale data from the outer IPv6 packet. This flaw allows an attacker to manipulate the source of the options length, resulting in a potential buffer overflow condition. The vulnerability may lead to unexpected behaviors, such as system crashes or unauthorized access, if exploited. Developers are encouraged to apply updates to mitigate this issue.

Affected Version(s)

Linux 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 < 10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667

Linux 891ef8dd2a8d14e4e73a81dcdb135b574c57f556

Linux 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 < 9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.