CVE-2026-64132
In the Linux kernel, the following vulnerability has been resolved:
ipv6: ioam: refresh hdr pointer before ioam6_event()
Reported by Sashiko:
In ipv6hopioam(), the hdr pointer is initialized to point into the
skb's linear data buffer. Later, the code calls skbensurewritable(),
which might reallocate the buffer:
if (skbensurewritable(skb, optoff + 2 + hdr->opt_len))
goto drop;
/ Trace pointer may have changed /
trace = (struct ioam6tracehdr *)(skbnetworkheader(skb)
+ optoff + sizeof(*hdr));
ioam6filltrace_data(skb, ns, trace, true);
ioam6event(IOAM6EVENTTRACE, devnet(skb->dev),
GFPATOMIC, (void *)trace, hdr->optlen - 2);
If the skb is cloned or lacks sufficient linear headroom,
skbensurewritable() will invoke pskbexpandhead(), which reallocates
the skb's data buffer and frees the old one, invalidating pointers to
it. While the code recalculates the trace pointer immediately after the
call to skbensurewritable(), it fails to recalculate the hdr pointer.
This patch fixes the above by recalculating the hdr pointer before
passing hdr->optlen to ioam6event(), so that we avoid any UaF.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/24de676da63c1122d2c13b0d546238b66d1b4e62, https://git.kernel.org/stable/c/5af905aa8e91ff8d94572a1e089558f21dcf24ed, https://git.kernel.org/stable/c/769723124b7c3b2bfea4cf68ad292698b87c8d01, https://git.kernel.org/stable/c/e46e6bc97fb1f339730ff1ba74267fbf48e7a422, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64132.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64132, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git