CVE-2026-72322 PUBLISHED

ipv6: mcast: Fix potential UAF in MLD delayed work

Assigner: Linux
Reserved: 09.08.2026 Published: 15.08.2026 Updated: 17.08.2026

In the Linux kernel, the following vulnerability has been resolved:

ipv6: mcast: Fix potential UAF in MLD delayed work

A race condition exists between device teardown and incoming MLD query processing, leading to a Use-After-Free in the MLD delayed work.

During device destruction, the primary reference to inet6_dev is dropped, which can drop its refcount to 0. The actual freeing of inet6_dev memory is deferred via RCU.

Concurrently, the packet receive path runs under RCU read lock and obtains the inet6_dev pointer. Because the memory is RCU-protected, CPU-0 can safely dereference inet6_dev even if its refcount has hit 0.

However, if CPU-0 calls igmp6_event_query() and schedules delayed work, it attempts to acquire a reference using in6_dev_hold(). This increments the refcount from 0 to 1, triggering a "refcount_t: addition on 0" warning. Since the inet6_dev memory is still scheduled to be freed after the RCU grace period, the device is freed while the work is still scheduled. When the work runs, it accesses the freed memory, causing a kernel panic.

Fix this by using refcount_inc_not_zero() (via a new helper in6_dev_hold_safe()) to prevent acquiring a reference if the device is already being destroyed. If the refcount is 0, we do not schedule the work.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

AV:N - The flaw is reached from the IPv6 receive path when ICMPv6 MLD query/report packets are processed (icmpv6_rcv → igmp6_event_query/igmp6_event_report); igmp6_event_query queues work before link-local validation, so any remotely deliverable ICMPv6 MLD packet to an IPv6-enabled interface can hit the vulnerable code. AC:L - A race between incoming MLD traffic and inet6_dev teardown during unregister; an attacker can flood MLD packets and concurrently unregister/delete the interface (e.g., via CAP_NET_ADMIN in a user/network namespace), controlling both sides of the race to reliably trigger the UAF. PR:N - Triggering MLD processing requires no authentication or local account—only the ability to send IPv6 ICMPv6 packets to the target; interface teardown can occur during routine operations (container stop, hot-unplug, reconfiguration) without attacker admin rights, and full control is also available with namespace CAP_NET_ADMIN (PR:L). UI:N - Exploitation requires no victim interaction beyond normal network operation; the attacker sends crafted or high-rate MLD traffic during interface teardown without the user opening files, clicking links, or performing any deliberate action. S:U - Impact is confined to kernel memory corruption and denial of service on the affected host; it does not cross a security boundary such as VM escape, container-to-host breakout, or IOMMU bypass—standard kernel privilege context remains unchanged. C:H - Use-after-free of the inet6_dev structure after RCU reclamation allows an attacker to dereference and potentially reuse freed kernel heap memory, providing a path to arbitrary kernel memory disclosure through controlled object reuse and heap grooming. I:H - The UAF on inet6_dev and its embedded delayed-work structures enables heap spraying and corruption of kernel function pointers and data, creating a credible path to arbitrary kernel code execution and privilege escalation beyond a simple crash. A:H - When the scheduled MLD delayed work runs after inet6_dev is freed, the kernel accesses freed memory causing a use-after-free that the fix commit explicitly documents as leading to kernel panic, resulting in complete loss of system availability.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to f12b63ef26a035c5a29b3ef56401e38199010d4a (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 0401d6cf7877c9be36652385dfcbf7f891b8b590 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to f03b0a45535d49bdab7e502efaacee205b2a7865 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 9815e834f5ff8b39e0ea9f0dbd532f4a3b8f0785 (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to ebbebf6cee950d7f1c81990256c0eae9e62572ae (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 9ce741c22df4fd9546e30306317ac7df3607e48f (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 0458ba1cda830ba4ccfcd9e19c0891438bcdbe4e (excl.)
  • affected from 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 9b26518b6896a16b809b1e42986f4ebac7bccc1e (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.12 is affected
  • unaffected from 0 to 2.6.12 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.97 to 6.12.* (incl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References