CVE-2026-97940
CVE CVE-2026-97940EUVD EUVD-2026-86794Published 2026-09-25T10:22:52.000ZLast changed 2026-09-25T14:41:42.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix fib6 walker UAF on seq stop ipv6_route_iter_active() treats a walker in FWS_U at the table root as already unlinked. fib6_del_route() can move a still-linked walker into that same state when the current leaf is the last route at the root, so ipv6_route_native_seq_stop() skips fib6_walker_unlink(). The seq private object can then be freed while it remains on net->ipv6.fib6_walkers. A later route deletion walks the dangling list and uses the freed walker. Use the list head as membership state and reinitialize it when unlinking. Keep the existing w->node check so a never-started iterator with a zeroed private object is not treated as linked. The same stop helper is used by /proc/net/ipv6_route and by the BPF ipv6_route iterator. The BPF show path only widens the race.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 8d2ca1d7b5c3e63b3a8a81ae99015b615c5f2bf7 <4553cfafa8d05c4ce20b1d18f79d9bb3b303fc02; 8d2ca1d7b5c3e63b3a8a81ae99015b615c5f2bf7 <b89b691dd00bf39b9ba39ab9446f8c62f419fa7b; patch: 7.2.7; patch: 6.18.53; 8d2ca1d7b5c3e63b3a8a81ae99015b615c5f2bf7 <19b4ed644d68098cc62ab612727f40d30f43476c; patch: 6.12.111; patch: 0; 3.13; patch: 7.3-rc3; 8d2ca1d7b5c3e63b3a8a81ae99015b615c5f2bf7 <0eede1689610e9eeaf729ba86fd1321799eb91a0
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.