Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89555

mpls: reload header after pskb_may_pull()
Back to all
CVE

CVE-2026-89555

mpls: reload header after pskb_may_pull()

In the Linux kernel, the following vulnerability has been resolved:

mpls: reload header after pskbmaypull()

mplsselectmultipath() calls mplsmultipathhash() to choose a nexthop

when an MPLS route has multiple nexthops.  While walking the MPLS label

stack, the hash routine caches hdr for the current label.  After finding

the bottom-of-stack label, it calls pskbmaypull() before reading the

inner IP header.

If an skb is constructed with the inner IP header in nonlinear data and

insufficient tailroom in the linear head, pskbmaypull() calls

pskbexpandhead() to replace the skb head and free the old one.  This

leaves hdr pointing to freed memory.  The IPv6 path can invalidate hdr

again when it performs a second pull for the larger header.

The issue was found through static analysis.  A reproducer sending a legal

Geneve packet through a bareudp/MPLS multipath setup triggered the same

KASAN report in 2 of 2 unpatched runs:

  BUG: KASAN: slab-use-after-free in mplsselectmultipath

  Read of size 1 at addr ffff88800ecc6e20 by task ksoftirqd/1/23

  Call Trace:

   mplsselectmultipath

   mpls_forward

   _netifreceiveskblist_core

   netifreceiveskblistinternal

   napicompletedone

   grocellpoll

   _napipoll

   netrxaction

  Freed by task 23:

   kfree

   pskbexpandhead

   _pskbpull_tail

   mplsselectmultipath

Reload hdr from the current skb head after each successful pull before

deriving the inner IPv4 or IPv6 header pointer.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/29e63b8d9fc150cc191b1c6eb7e16e1247e1b650, https://git.kernel.org/stable/c/49d38c1b4390412f8950d33dfaee0ccbd17beb81, https://git.kernel.org/stable/c/aa4fe0b450a461aa1162fe8375f5d28f4c957df8, https://git.kernel.org/stable/c/b1c0783b2facc398437ad8f8b86c636d7a78f8db, https://git.kernel.org/stable/c/bfaaff99238326166694354a63a76c02563f98b1, https://git.kernel.org/stable/c/d82b90a38c2ca8a0694428eab0e9551c23f2447d, https://git.kernel.org/stable/c/d9640239827d6d0cb84263b590f7a4f1596c17eb, https://git.kernel.org/stable/c/fed638a248116b8a249bd4202d28e5934bdc65ad, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89555.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89555, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00694%
EPSS Percentile
0.51458%
Introduced Version
9f427a0e474a67b454420c131709600d44850486,4.9.8,ad864d9fce0ec56cc8f6afe5c6a0e6d7f484b9eb,4.10.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
29e63b8d9fc150cc191b1c6eb7e16e1247e1b650,4.10,5.10.270,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading