CVE-2026-80840 PUBLISHED

ipv6: seg6: clear IPv4 control block on IPIP decapsulation

Assigner: Linux
Reserved: 26.08.2026 Published: 04.09.2026 Updated: 04.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ipv6: seg6: clear IPv4 control block on IPIP decapsulation

End.DX4 and End.DT4 decapsulate an IPv4 packet through decap_and_validate() and send it directly to IPv4 routing. The inner packet therefore bypasses ip_rcv_core(), which normally clears IPCB before IPv4 interprets skb->cb.

The skb instead retains IP6CB data from the outer packet. IP6CB and IPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps IPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and ts.

The sender can make the stale optlen byte nonzero with a valid outer extension-header chain. The reproducers put an eight-byte Destination Options header immediately after the 40-byte IPv6 header and before the Segment Routing Header. ipv6_destopt_rcv() records the sender-controlled Destination Options offset in both lastopt and nhoff, setting them to 40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees optlen = 40 and rr = 40.

Both tcp_v4_save_options() and __ip_options_echo() skip option copying when optlen is zero. Here optlen is 40, so the TCP SYN path allocates room for 40 bytes of option data and calls __ip_options_echo(). The stale rr value makes that function read inner packet byte 41 as the Record Route option length. The reproducers set that sender-controlled byte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte option-data area.

Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5 kernel both produced:

BUG: KASAN: slab-out-of-bounds in __ip_options_echo() Write of size 255

The relevant End.DX4 call path is:

__ip_options_echo tcp_v4_route_req tcp_conn_request tcp_v4_conn_request tcp_rcv_state_process tcp_v4_do_rcv tcp_v4_rcv ip_protocol_deliver_rcu ip_local_deliver_finish ip_local_deliver input_action_end_dx4_finish input_action_end_dx4

The relevant End.DT4 call path is:

__ip_options_echo tcp_v4_route_req tcp_conn_request tcp_v4_conn_request tcp_rcv_state_process tcp_v4_do_rcv tcp_v4_rcv ip_protocol_deliver_rcu ip_local_deliver_finish ip_local_deliver input_action_end_dt4

tcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so it does not appear as a separate frame.

When decap_and_validate() handles IPPROTO_IPIP, save the ingress interface from IP6CB, clear IPCB, and restore the saved value. Doing this in the common decapsulation path covers End.DX4, End.DT4, and End.DT46's IPv4 arm.

Use IP6CB(skb)->iif rather than skb->skb_iif. These actions run after l3mdev processing, which can replace skb_iif with the L3 master; IP6CB iif still records the receiving interface set at IPv6 ingress.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to 10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667 (excl.)
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to eb0f422487228e140f3d609b032ac61aedcab8fa (excl.)
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to 9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c (excl.)
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to f52f1e75716d2ee49e013edf204ac92337c72fd8 (excl.)
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to 0e3f01fe2e704e76af4385b8a1742641885a191c (excl.)
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to 3e4476e58343fb8f2fffced9e22d935376b17aaf (excl.)
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to bf1c1151560d11036a144d917fa4c131831342d7 (excl.)
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to f4be3b391265e24c7720fc867c50062b436acf33 (excl.)
  • affected from 891ef8dd2a8d14e4e73a81dcdb135b574c57f556 to 44930446dde45a7a90fe1446fa38eb0e2c561646 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.14 is affected
  • unaffected from 0 to 4.14 (excl.)
  • unaffected from 5.10.269 to 5.10.* (incl.)
  • unaffected from 5.15.220 to 5.15.* (incl.)
  • unaffected from 6.1.187 to 6.1.* (incl.)
  • unaffected from 6.6.156 to 6.6.* (incl.)
  • unaffected from 6.12.108 to 6.12.* (incl.)
  • unaffected from 6.18.49 to 6.18.* (incl.)
  • unaffected from 7.1.13 to 7.1.* (incl.)
  • unaffected from 7.2.3 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References