In the Linux kernel, the following vulnerability has been resolved:
ipv6: mcast: Fix potential UAF in MLD delayed work
A race condition exists between device teardown and incoming MLD query
processing, leading to a Use-After-Free in the MLD delayed work.
During device destruction, the primary reference to inet6_dev is dropped,
which can drop its refcount to 0. The actual freeing of inet6_dev memory
is deferred via RCU.
Concurrently, the packet receive path runs under RCU read lock and obtains
the inet6_dev pointer. Because the memory is RCU-protected, CPU-0 can
safely dereference inet6_dev even if its refcount has hit 0.
However, if CPU-0 calls igmp6_event_query() and schedules delayed work, it
attempts to acquire a reference using in6_dev_hold(). This increments the
refcount from 0 to 1, triggering a "refcount_t: addition on 0" warning.
Since the inet6_dev memory is still scheduled to be freed after the RCU
grace period, the device is freed while the work is still scheduled.
When the work runs, it accesses the freed memory, causing a kernel panic.
Fix this by using refcount_inc_not_zero() (via a new helper
in6_dev_hold_safe()) to prevent acquiring a reference if the device is
already being destroyed. If the refcount is 0, we do not schedule the work.
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
AV:N - The flaw is reached from the IPv6 receive path when ICMPv6 MLD query/report packets are processed (icmpv6_rcv → igmp6_event_query/igmp6_event_report); igmp6_event_query queues work before link-local validation, so any remotely deliverable ICMPv6 MLD packet to an IPv6-enabled interface can hit the vulnerable code.
AC:L - A race between incoming MLD traffic and inet6_dev teardown during unregister; an attacker can flood MLD packets and concurrently unregister/delete the interface (e.g., via CAP_NET_ADMIN in a user/network namespace), controlling both sides of the race to reliably trigger the UAF.
PR:N - Triggering MLD processing requires no authentication or local account—only the ability to send IPv6 ICMPv6 packets to the target; interface teardown can occur during routine operations (container stop, hot-unplug, reconfiguration) without attacker admin rights, and full control is also available with namespace CAP_NET_ADMIN (PR:L).
UI:N - Exploitation requires no victim interaction beyond normal network operation; the attacker sends crafted or high-rate MLD traffic during interface teardown without the user opening files, clicking links, or performing any deliberate action.
S:U - Impact is confined to kernel memory corruption and denial of service on the affected host; it does not cross a security boundary such as VM escape, container-to-host breakout, or IOMMU bypass—standard kernel privilege context remains unchanged.
C:H - Use-after-free of the inet6_dev structure after RCU reclamation allows an attacker to dereference and potentially reuse freed kernel heap memory, providing a path to arbitrary kernel memory disclosure through controlled object reuse and heap grooming.
I:H - The UAF on inet6_dev and its embedded delayed-work structures enables heap spraying and corruption of kernel function pointers and data, creating a credible path to arbitrary kernel code execution and privilege escalation beyond a simple crash.
A:H - When the scheduled MLD delayed work runs after inet6_dev is freed, the kernel accesses freed memory causing a use-after-free that the fix commit explicitly documents as leading to kernel panic, resulting in complete loss of system availability.
| Attack Vector |
Network |
Scope |
Unchanged |
| Attack Complexity |
Low |
Confidentiality Impact |
High |
| Privileges Required |
None |
Integrity Impact |
High |
| User Interaction |
None |
Availability Impact |
High |
AV:N - The flaw is reached from the IPv6 receive path when ICMPv6 MLD query/report packets are processed (icmpv6_rcv → igmp6_event_query/igmp6_event_report); igmp6_event_query queues work before link-local validation, so any remotely deliverable ICMPv6 MLD packet to an IPv6-enabled interface can hit the vulnerable code.
AC:L - A race between incoming MLD traffic and inet6_dev teardown during unregister; an attacker can flood MLD packets and concurrently unregister/delete the interface (e.g., via CAP_NET_ADMIN in a user/network namespace), controlling both sides of the race to reliably trigger the UAF.
PR:N - Triggering MLD processing requires no authentication or local account—only the ability to send IPv6 ICMPv6 packets to the target; interface teardown can occur during routine operations (container stop, hot-unplug, reconfiguration) without attacker admin rights, and full control is also available with namespace CAP_NET_ADMIN (PR:L).
UI:N - Exploitation requires no victim interaction beyond normal network operation; the attacker sends crafted or high-rate MLD traffic during interface teardown without the user opening files, clicking links, or performing any deliberate action.
S:U - Impact is confined to kernel memory corruption and denial of service on the affected host; it does not cross a security boundary such as VM escape, container-to-host breakout, or IOMMU bypass—standard kernel privilege context remains unchanged.
C:H - Use-after-free of the inet6_dev structure after RCU reclamation allows an attacker to dereference and potentially reuse freed kernel heap memory, providing a path to arbitrary kernel memory disclosure through controlled object reuse and heap grooming.
I:H - The UAF on inet6_dev and its embedded delayed-work structures enables heap spraying and corruption of kernel function pointers and data, creating a credible path to arbitrary kernel code execution and privilege escalation beyond a simple crash.
A:H - When the scheduled MLD delayed work runs after inet6_dev is freed, the kernel accesses freed memory causing a use-after-free that the fix commit explicitly documents as leading to kernel panic, resulting in complete loss of system availability.
CVSS 3.1