CVE-2026-53006
Critical · CVSS 9.8Linux Kernel — Use-After-Free (UAF) in ICMPv6 receive path after pskb_pull() head pointer change
- CVSS
- 9.8
- nvd
- EPSS
- 0.38%
- 31th pct
- KEV
- No
- Class
- oss containerizable
- CWE-416, CWE-825
Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr when net_dbg_ratelimited() is called in the slow path. - Avoid potential future misuse after pskb_pull() call.
Search profile — drives PoC discovery
Symbols icmpv6_rcvpskb_pullipv6_hdrsaddrdaddrnet_dbg_ratelimitedskb->head
Keywords CVE-2026-53006icmpv6_rcv UAFipv6 icmpv6 use-after-freepskb_pull skb head changeLinux kernel ICMPv6 saddr daddr UAFCWE-825 Linux kernel ipv6
Versions: Linux kernel versions addressed by commits: 0069813e6ca9, 085e31a811ef, 1e1f0f89ee46, 38bdbc897c0d, 7bff2c8fe5c3
Affected packages
| Linux | Kernel | 4.4.0 → 5.10.258 |
| Linux | Kernel | 5.11.0 → 5.15.209 |
| Linux | Kernel | 5.16.0 → 6.1.175 |
| Linux | Kernel | 6.13.0 → 6.18.33 |
| Linux | Kernel | 6.19.0 → 7.0.10 |
| Linux | Kernel | 6.2.0 → 6.6.141 |
| Linux | Kernel | 6.7.0 → 6.12.91 |
References
- https://git.kernel.org/stable/c/0069813e6ca9309eca78022bcb3aeb1e9ef90a12
- https://git.kernel.org/stable/c/085e31a811ef234ef8c3e219c4636dfebfe7e10f
- https://git.kernel.org/stable/c/1e1f0f89ee4692a64be3f3707ff8ac1ae57b03e7
- https://git.kernel.org/stable/c/38bdbc897c0d83a3e2b925a51b69420f1feba29a
- https://git.kernel.org/stable/c/7bff2c8fe5c35ae58bf73104f53db3676e6e5d94
- https://git.kernel.org/stable/c/7c66b368c6ff453f99cb39d84af93e908e51eef2
- https://git.kernel.org/stable/c/aff0f28f5be803de2452ce702631c021fcd9ce8a
- https://git.kernel.org/stable/c/f996edd7615e686ada141b7f3395025729ff8ccb
- https://access.redhat.com/errata/RHSA-2026:45192
- https://access.redhat.com/errata/RHSA-2026:47010
- https://access.redhat.com/errata/RHSA-2026:47011
- https://access.redhat.com/errata/RHSA-2026:47017
Status: enriched · ingested 2026-07-11T00:00:26.000Z · profiled 2026-07-11T00:30:26.000Z