CVE-2026-80792

    Dashboard / Vulnerabilities / CVE-2026-80792

    CVE-2026-80792

    Published: 4 Sept 2026Last Modified: 15 Sept 2026

    Summary: ipv6: fix use-after-free in ip6_finish_output2()

    Details: In the Linux kernel, the following vulnerability has been resolved: ipv6: fix use-after-free in ip6_finish_output2() ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmit path or other encapsulation operations within lwtunnel_xmit() can reallocate the skb head, freeing the memory that daddr points to. When lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale daddr pointer to compute the nexthop and to look up or create the neighbour entry. This results in a use-after-free read, which can leak sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or crash the system. Fix this by re-fetching the IPv6 header and the destination address pointer after lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop computation and neighbour lookup operate on valid memory.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 4132c4ad00ddbf3a175ea0d2c775b662a32f4c85

    Affected versions

    v5.10.266
    v5.10.265
    v5.10.264
    v5.10.263
    v5.10.262
    v5.10.261
    v5.10.260
    v5.10.259
    v5.10.258
    v5.10.257
    v5.10.256
    v5.10.255
    v5.10.254
    v5.10.253
    v5.10.252
    v5.10.251
    v5.10.250
    v5.10.249
    v5.10.248
    v5.10.247
    v5.10.246
    v5.10.245
    v5.10.244
    v5.10.243
    v5.10.242
    v5.10.241
    v5.10.240
    v5.10.239
    v5.10.238
    v5.10.237
    v5.10.236
    v5.10.235
    v5.10.234
    v5.10.233

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-80792 | CVE-DB