Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80976

seg6: reset IP6CB after IPv6 decapsulation
Back to all
CVE

CVE-2026-80976

seg6: reset IP6CB after IPv6 decapsulation

In the Linux kernel, the following vulnerability has been resolved:

seg6: reset IP6CB after IPv6 decapsulation

decapandvalidate() pulls the outer SRv6 headers and makes the inner

packet the skb network header. The IPv6 control block still contains

values collected while parsing the outer packet, including nhoff and

extension-header flags.

End.DX6 and End.DT6 route the inner IPv6 packet directly to the IPv6

input path. An unprivileged user can reach End.DT6 from a user and net

namespace by installing a local SID and injecting an outer packet with

Hop-by-Hop and Destination Options headers followed by an SRH and a

minimal inner IPv6 packet.

The outer extension headers leave a large nhoff in IP6CB. After

decapsulation, ip6protocoldeliver_rcu() uses that stale offset on the

inner packet and reads beyond the skb head. KASAN reports:

  BUG: KASAN: slab-out-of-bounds in ip6protocoldeliver_rcu

  ip6protocoldeliver_rcu+0x1118/0x1450

  ip6inputfinish+0x11b/0x240

  seg6localinput_core+0xed/0x2e0

  lwtunnel_input+0x1e9/0x4e0

  ipv6rthdrrcv+0x525f/0x6c50

  ip6protocoldeliver_rcu+0xcb7/0x1450

Before clearing IP6CB for an inner IPv6 packet, save its incoming

interface index and L3 slave state. Restore both after the clear and set

nhoff to the inner IPv6 base-header nexthdr field.

Use IP6CB(skb)->iif rather than skb->skb_iif because VRF processing can

replace skb_iif with the L3 master while IP6CB keeps the receiving

interface. Preserve IP6SKB_L3SLAVE for the same reason.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/2b154e96fcb3f01fd42765c64e0a56820fbc16eb, https://git.kernel.org/stable/c/96c74420ac92930a7e0f21770818544eee4a93d7, https://git.kernel.org/stable/c/9ae92198c24d7dacd4070e2f34f6e1ed3a63061c, https://git.kernel.org/stable/c/a0e2b0a3718f0cf9fb0ee41710b4a6348a7315c8, https://git.kernel.org/stable/c/c73fb911e02b9a766c950bc9707f3e3a96ffd702, https://git.kernel.org/stable/c/cfa186a0857a0f831dfca67b16bbc40ecfdf3280, https://git.kernel.org/stable/c/d1f0d353358987ca87f21d8956e2d2854951130d, https://git.kernel.org/stable/c/f967455fb2a5a2079b9eb5823e9ccf359174bf9f, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80976.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80976, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00714%
EPSS Percentile
0.52233%
Introduced Version
d7a669dd2f8ba07a17423f4ad586dfc0379882f7,4.14.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
f967455fb2a5a2079b9eb5823e9ccf359174bf9f,5.10.270,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading