DEBIAN-CVE-2026-68127
In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskbmaypull in checksum adjust ilacsumadjusttransport() caches ip6h = ipv6hdr(skb) before calling pskbmaypull(). On a non-linear skb whose transport header sits in a page fragment, pskbmaypull() can call _pskbpulltail() / pskbexpandhead() and free the old skb head, leaving ip6h dangling; the following getcsumdiff(ip6h, p) then reads freed memory. ilaupdateipv6locator() uses ip6h (and the iaddr derived from it) again after the csum-adjust call and additionally writes the new locator through that pointer. Impact: a remote IPv6 packet routed through a configured ILA csum-adjust-transport route or receive-side mapping triggers a slab-use-after-free in ilaupdateipv6locator() (KASAN). The route or mapping requires CAPNETADMIN to configure, but trigger packets are unauthenticated once it exists. Reload ip6h after each pskbmaypull() in ilacsumadjusttransport() before the csum-diff read. In ilaupdateipv6locator() only the ILACSUMADJUSTTRANSPORT case pulls the skb, so reload ip6h and iaddr in that case alone before the destination-address write; the neutral-map modes never pull and keep their cached pointers.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-68127