Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-89555

In the Linux kernel, the following vulnerability has been resolved: mpls: reload header after pskb_may_pull() mpls_select_multipath() calls mpls_multipath_hash() to choose a nexthop when an MPLS rou...
Back to all
CVE

DEBIAN-CVE-2026-89555

In the Linux kernel, the following vulnerability has been resolved: mpls: reload header after pskb_may_pull() mpls_select_multipath() calls mpls_multipath_hash() to choose a nexthop when an MPLS rou...

In the Linux kernel, the following vulnerability has been resolved:  mpls: reload header after pskbmaypull()  mplsselectmultipath() calls mplsmultipathhash() to choose a nexthop when an MPLS route has multiple nexthops.  While walking the MPLS label stack, the hash routine caches hdr for the current label.  After finding the bottom-of-stack label, it calls pskbmaypull() before reading the inner IP header.  If an skb is constructed with the inner IP header in nonlinear data and insufficient tailroom in the linear head, pskbmaypull() calls pskbexpandhead() to replace the skb head and free the old one.  This leaves hdr pointing to freed memory.  The IPv6 path can invalidate hdr again when it performs a second pull for the larger header.  The issue was found through static analysis.  A reproducer sending a legal Geneve packet through a bareudp/MPLS multipath setup triggered the same KASAN report in 2 of 2 unpatched runs:    BUG: KASAN: slab-use-after-free in mplsselectmultipath   Read of size 1 at addr ffff88800ecc6e20 by task ksoftirqd/1/23    Call Trace:    mplsselectmultipath    mplsforward    netifreceiveskblistcore    netifreceiveskblistinternal    napicompletedone    grocellpoll    napipoll    netrxaction    Freed by task 23:    kfree    pskbexpandhead    _pskbpulltail    mplsselect_multipath  Reload hdr from the current skb head after each successful pull before deriving the inner IPv4 or IPv6 header pointer.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-89555

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.111-1,7.2.6-1,6.12.111-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading