DEBIAN-CVE-2026-74581
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6rulesuppress() drops a suppressed route with ip6rtputflags(), but leaves res->rt6 pointing at the released rt6info. If no later rule supplies a replacement, fib6rulelookup() still sees res.rt6 and returns that stale dst to its caller. A suppressing rule can therefore leak a released route back to rt6lookup(), and the next put hits rcurefputslowpath() from dstrelease(). Clear res->rt6 when suppressing the route so suppressed lookups fall through to the null dst instead of reusing the released one.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-74581