Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-74581

net: ipv6: clear suppressed fib6 rule result
Back to all
CVE

CVE-2026-74581

net: ipv6: clear suppressed fib6 rule result

In the Linux kernel, the following vulnerability has been resolved:

net: ipv6: clear suppressed fib6 rule result

fib6rulesuppress() drops a suppressed route with ip6rtput_flags(),

but leaves res->rt6 pointing at the released rt6_info.

If no later rule supplies a replacement, fib6rulelookup() still sees

res.rt6 and returns that stale dst to its caller. A suppressing rule can

therefore leak a released route back to rt6_lookup(), and the next put

hits rcurefputslowpath() from dst_release().

Clear res->rt6 when suppressing the route so suppressed lookups fall

through to the null dst instead of reusing the released one.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/354db6243eca59e9d187ffbf8b7955b044ce84dc, https://git.kernel.org/stable/c/5d29b286c9de0b309e94b9ed083aa1a2f429434f, https://git.kernel.org/stable/c/6aea62e433fe1b586202a5fee8b5807ce635e1d7, https://git.kernel.org/stable/c/6d98c70fe0ba8c7708bfd5b2a5174d2086775daa, https://git.kernel.org/stable/c/90c57310e266eb94e4a80d6b15a9ca131d2e82cb, https://git.kernel.org/stable/c/9bad152c42b37499162367fe47867411e62fffa3, https://git.kernel.org/stable/c/a341c091ca0bfae377747b1b59a3bd8ebe18a937, https://git.kernel.org/stable/c/dc3ab04220667f254f4348572b2a0b3febff89fb, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74581.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74581, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00755%
EPSS Percentile
0.53289%
Introduced Version
209d35ee34e25f9668c404350a1c86d914c54ffa,8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383,cdef485217d30382f3bf6448c54b4401648fe3f1,0,5.10.84,5.15.7,5.4.164,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0
Fix Available
90c57310e266eb94e4a80d6b15a9ca131d2e82cb,5d29b286c9de0b309e94b9ed083aa1a2f429434f,6aea62e433fe1b586202a5fee8b5807ce635e1d7,5.10.265,5.15.216,5.5,6.6.151,6.12.103,6.18.44,7.1.8,0:4.18.0-553.159.1.el8_10,0:4.18.0-553.159.1.rt7.500.el8_10,0:1-14.el8_10,0:1-12.el8_10,0:1-9.el8_10,0:1-1.el8_10,0:1-16.el8_10,0:5.14.0-687.42.1.el9_8,6.12.0-211.51.1.el10_2,6.1.187-1,6.12.107-1~deb12u1,6.12.105-1,0:6.12.0-211.51.1.el10_2,0:6.12.0-206.104.3.3.el10uek,0:5.15.0-324.217.5.2.el8uek,0:5.15.0-324.217.5.2.el9uek,0:6.12.0-206.104.3.3.el9uek,0:5.10.265-265.1078.amzn2,0:1.0-0.amzn2,0:5.15.220-153.252.amzn2,1:6.18.44-99.149.amzn2023,1:1.0-0.amzn2023,1:6.12.103-127.188.amzn2023,1:6.1.186-228.374.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading