CVE-2026-64554 (GCVE-0-2026-64554)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() br_ip6_fragment() gets prevhdr, a pointer into the skb head, from ip6_find_1stfragopt(), then calls skb_checksum_help(). For a cloned skb skb_checksum_help() reallocates the head via pskb_expand_head(), leaving prevhdr dangling. It is later dereferenced in ip6_frag_next(), causing a use-after-free write. Save prevhdr's offset before skb_checksum_help() and recompute it after, like commit ef0efcd3bd3f ("ipv6: Fix dangling pointer when ipv6 fragment"). BUG: KASAN: slab-use-after-free in ip6_frag_next (net/ipv6/ip6_output.c:857) Write of size 1 at addr ffff888013ff5016 by task exploit/141 Call Trace: ... kasan_report (mm/kasan/report.c:595) ip6_frag_next (net/ipv6/ip6_output.c:857) br_ip6_fragment (net/ipv6/netfilter.c:212) nf_ct_bridge_post (net/bridge/netfilter/nf_conntrack_bridge.c:407) nf_hook_slow (net/netfilter/core.c:619) br_forward_finish (net/bridge/br_forward.c:66) __br_forward (net/bridge/br_forward.c:115) maybe_deliver (net/bridge/br_forward.c:191) br_flood (net/bridge/br_forward.c:245) br_handle_frame_finish (net/bridge/br_input.c:229) br_handle_frame (net/bridge/br_input.c:442) ... packet_sendmsg (net/packet/af_packet.c:3114) ... do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Kernel panic - not syncing: Fatal exception in interrupt
Impacted products
Vendor Product Version
Linux Linux Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33
Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33
Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33
Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33
Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33
Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33
Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33
Version: 764dd163ac922f8683b5bcd3007251ce7b26cd33
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/ipv6/netfilter.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "8c10778ec674b67a07ea042fcba64270f3f38a5a",
              "status": "affected",
              "version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
              "versionType": "git"
            },
            {
              "lessThan": "2731efa6364e47934c96eb69e01ea131e8af8030",
              "status": "affected",
              "version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
              "versionType": "git"
            },
            {
              "lessThan": "00c06ef8c018493943891a7d0ca82b71b24f3180",
              "status": "affected",
              "version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
              "versionType": "git"
            },
            {
              "lessThan": "c141f69d0a0fb16964dbc293650047e69bda8af7",
              "status": "affected",
              "version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
              "versionType": "git"
            },
            {
              "lessThan": "f2e6596d10783557aeb9668da2a3b4d19deb2001",
              "status": "affected",
              "version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
              "versionType": "git"
            },
            {
              "lessThan": "1c4f67c89fd27c4df4c70b135c2c59627698b3c0",
              "status": "affected",
              "version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
              "versionType": "git"
            },
            {
              "lessThan": "4ac981a8b7ce7aec99a52d08f8a8953e8e120067",
              "status": "affected",
              "version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
              "versionType": "git"
            },
            {
              "lessThan": "86f3ce81dd2b4b0aa2c3016c989a943e4b1b643d",
              "status": "affected",
              "version": "764dd163ac922f8683b5bcd3007251ce7b26cd33",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/ipv6/netfilter.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "lessThan": "5.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.261",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.212",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.178",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.145",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.97",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.40",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.5",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()\n\nbr_ip6_fragment() gets prevhdr, a pointer into the skb head, from\nip6_find_1stfragopt(), then calls skb_checksum_help().  For a cloned skb\nskb_checksum_help() reallocates the head via pskb_expand_head(), leaving\nprevhdr dangling.  It is later dereferenced in ip6_frag_next(), causing a\nuse-after-free write.\n\nSave prevhdr\u0027s offset before skb_checksum_help() and recompute it after,\nlike commit ef0efcd3bd3f (\"ipv6: Fix dangling pointer when ipv6\nfragment\").\n\n  BUG: KASAN: slab-use-after-free in ip6_frag_next (net/ipv6/ip6_output.c:857)\n  Write of size 1 at addr ffff888013ff5016 by task exploit/141\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   ip6_frag_next (net/ipv6/ip6_output.c:857)\n   br_ip6_fragment (net/ipv6/netfilter.c:212)\n   nf_ct_bridge_post (net/bridge/netfilter/nf_conntrack_bridge.c:407)\n   nf_hook_slow (net/netfilter/core.c:619)\n   br_forward_finish (net/bridge/br_forward.c:66)\n   __br_forward (net/bridge/br_forward.c:115)\n   maybe_deliver (net/bridge/br_forward.c:191)\n   br_flood (net/bridge/br_forward.c:245)\n   br_handle_frame_finish (net/bridge/br_input.c:229)\n   br_handle_frame (net/bridge/br_input.c:442)\n   ...\n   packet_sendmsg (net/packet/af_packet.c:3114)\n   ...\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  Kernel panic - not syncing: Fatal exception in interrupt"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:A - The vulnerable code is the bridge forwarding/refragmentation path, driven entirely by frames received on a bridge port from an L2 peer \u2014 typically a guest VM over tap/virtio or a container over veth, which per skbuff.h are exactly the sources that deliver CHECKSUM_PARTIAL skbs on receive. This is logically adjacent topology (bridged segment/overlay), not a routed internet path, so AV:A rather than N.\nAC:L - The attacker controls every precondition: send IPv6 fragments (forces conntrack reassembly and sets frag_max_size), set VIRTIO_NET_HDR_F_NEEDS_CSUM for CHECKSUM_PARTIAL, and target a broadcast/multicast/unknown-unicast MAC so br_flood calls deliver_clone() and makes the skb cloned. No race and no attacker-independent condition is involved; the corruption is deterministic once the packet is crafted.\nPR:N - A guest VM or container attached to the host bridge holds no credentials on the vulnerable host and needs none \u2014 it merely emits frames onto the segment. In the equivalent local variant the entire setup (bridge, veth, nft bridge conntrack, AF_PACKET with CAP_NET_RAW) is reachable from an unprivileged user namespace, so no real privilege is required either way.\nUI:N - The corruption happens automatically in softirq context while the bridge forwards the attacker\u0027s packet. No action by any user or administrator on the target is needed.\nS:U - The vulnerable component and the impacted resource are both the host kernel\u0027s network stack; no hypervisor, IOMMU, or sandbox boundary is bypassed by the bug itself. Standard kernel memory corruption is scored Unchanged.\nC:H - This is a use-after-free/out-of-bounds write on the slab; the freed skb head and the write target can be groomed by the attacker, and such heap corruption is routinely leveraged into arbitrary kernel memory disclosure. Per kernel scoring guidance, UAF/OOB corruption is High confidentiality impact.\nI:H - ip6_frag_next() writes NEXTHDR_FRAGMENT (0x2c) at skb_network_header(frag) plus an uncontrolled inter-allocation delta, giving a repeatable 1-byte heap write at a heap-groomable offset \u2014 once per emitted fragment. A controlled byte write into adjacent slab objects is a classic primitive for corrupting kernel data structures and escalating to control-flow hijack.\nA:H - KASAN reports a slab-use-after-free write followed by \"Kernel panic - not syncing: Fatal exception in interrupt\" because the fault occurs in softirq forwarding context, taking down the whole host rather than one task. The attacker can repeat it at will with a stream of crafted fragments."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-17T04:57:32.112Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/8c10778ec674b67a07ea042fcba64270f3f38a5a"
        },
        {
          "url": "https://git.kernel.org/stable/c/2731efa6364e47934c96eb69e01ea131e8af8030"
        },
        {
          "url": "https://git.kernel.org/stable/c/00c06ef8c018493943891a7d0ca82b71b24f3180"
        },
        {
          "url": "https://git.kernel.org/stable/c/c141f69d0a0fb16964dbc293650047e69bda8af7"
        },
        {
          "url": "https://git.kernel.org/stable/c/f2e6596d10783557aeb9668da2a3b4d19deb2001"
        },
        {
          "url": "https://git.kernel.org/stable/c/1c4f67c89fd27c4df4c70b135c2c59627698b3c0"
        },
        {
          "url": "https://git.kernel.org/stable/c/4ac981a8b7ce7aec99a52d08f8a8953e8e120067"
        },
        {
          "url": "https://git.kernel.org/stable/c/86f3ce81dd2b4b0aa2c3016c989a943e4b1b643d"
        }
      ],
      "title": "netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-64554",
    "datePublished": "2026-07-27T20:10:41.726Z",
    "dateReserved": "2026-07-19T15:36:31.796Z",
    "dateUpdated": "2026-08-17T04:57:32.112Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…