CVE-2026-89555
In the Linux kernel, the following vulnerability has been resolved:
mpls: reload header after pskbmaypull()
mplsselectmultipath() calls mplsmultipathhash() to choose a nexthop
when an MPLS route has multiple nexthops. While walking the MPLS label
stack, the hash routine caches hdr for the current label. After finding
the bottom-of-stack label, it calls pskbmaypull() before reading the
inner IP header.
If an skb is constructed with the inner IP header in nonlinear data and
insufficient tailroom in the linear head, pskbmaypull() calls
pskbexpandhead() to replace the skb head and free the old one. This
leaves hdr pointing to freed memory. The IPv6 path can invalidate hdr
again when it performs a second pull for the larger header.
The issue was found through static analysis. A reproducer sending a legal
Geneve packet through a bareudp/MPLS multipath setup triggered the same
KASAN report in 2 of 2 unpatched runs:
BUG: KASAN: slab-use-after-free in mplsselectmultipath
Read of size 1 at addr ffff88800ecc6e20 by task ksoftirqd/1/23
Call Trace:
mplsselectmultipath
mpls_forward
_netifreceiveskblist_core
netifreceiveskblistinternal
napicompletedone
grocellpoll
_napipoll
netrxaction
Freed by task 23:
kfree
pskbexpandhead
_pskbpull_tail
mplsselectmultipath
Reload hdr from the current skb head after each successful pull before
deriving the inner IPv4 or IPv6 header pointer.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/29e63b8d9fc150cc191b1c6eb7e16e1247e1b650, https://git.kernel.org/stable/c/49d38c1b4390412f8950d33dfaee0ccbd17beb81, https://git.kernel.org/stable/c/aa4fe0b450a461aa1162fe8375f5d28f4c957df8, https://git.kernel.org/stable/c/b1c0783b2facc398437ad8f8b86c636d7a78f8db, https://git.kernel.org/stable/c/bfaaff99238326166694354a63a76c02563f98b1, https://git.kernel.org/stable/c/d82b90a38c2ca8a0694428eab0e9551c23f2447d, https://git.kernel.org/stable/c/d9640239827d6d0cb84263b590f7a4f1596c17eb, https://git.kernel.org/stable/c/fed638a248116b8a249bd4202d28e5934bdc65ad, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89555.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89555, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git