CVE-2026-80792
CVE CVE-2026-80792EUVD EUVD-2026-71435Published 2026-09-04T15:13:04.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix use-after-free in ip6_finish_output2() ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmit path or other encapsulation operations within lwtunnel_xmit() can reallocate the skb head, freeing the memory that daddr points to. When lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale daddr pointer to compute the nexthop and to look up or create the neighbour entry. This results in a use-after-free read, which can leak sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or crash the system. Fix this by re-fetching the IPv6 header and the destination address pointer after lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop computation and neighbour lookup operate on valid memory.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 5.4.289 <5.5; patch: 6.6.154; e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 <73a187384a8c8b983c7fea046d716b6752a1e7a3; e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 <d960881b9312e781a3429aabceb223ce6b7c882f; e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 <99219c82804f266189388e8bf1cf5135d10d5515; 5.15; e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 <d0d48d999b0eee6bb176ef4e39d9be868fa80f7e; patch: 6.1.185; patch: 0; e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 <3c770ac4e6f07af7c7b40c474a3efc61ffed7862; patch: 5.15.218; patch: 7.2.1; patch: 5.10.267; patch: 6.12.106; patch: 6.18.47; 4132c4ad00ddbf3a175ea0d2c775b662a32f4c85 <75e0a544ebe9af663ef53ca21e9e9185c51fb54a; patch: 7.1.11; e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 <c95f01b78266828a57060d754fcbfc92123a98ed; e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 <3dc98e5fe82d069dd29b124ffbdb679331dfea43; 1598154fd28ffa4a55beae1970475fd6776554b6; e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 <087ee0d914aaae929f1660c9ca878e367655ba1a; patch: 7.3-rc1; 5.10.233 <5.10.267
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.