In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix Route Information option length validation
rt6_route_rcv() validates the Route Information option (RFC 4191) length against the prefix length, but both checks are off by one.
rinfo->length is the ND option length in units of 8 octets and it *includes* the 8-byte option header, so an option carrying N bytes of prefix has length == 1 + N/8. RFC 4191 section 2.3 requires length 3 when Prefix Length is greater than 64, and 2 or 3 when it is greater than 0. The code accepts length >= 2 and length >= 1 respectively.
ipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix, so a Router Advertisement with (prefix_len=128, length=2) or (prefix_len=64, length=1) makes the kernel read up to 8 bytes past the end of the option. Those bytes end up in the prefix of the route that gets installed, so they are visible to userspace:
# RA with a Route Information option (prefix_len=128, length=2) # followed by a source link-layer address option, 01 01 de ad be ef ca fe $ ip -6 route show 2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds
When the Route Information option is the last one in the packet, those eight bytes come from the skb tail room instead.
Reject the option lengths RFC 4191 does not allow.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18-modules-extra-commonUpgrade kernel6.18-toolsUpgrade kernel6.18-headersUpgrade kernel-livepatch-6.18.48-107.148Upgrade kernel6.18Upgrade microvm-kernel6.18Upgrade kernel6.18-tools-develUpgrade kernel6.18-modules-extraUpgrade kernel6.18-debuginfoUpgrade bpftool6.18Upgrade bpftool6.18-debuginfoUpgrade kernel6.18-tools-debuginfoUpgrade python3-perf6.18-debuginfoUpgrade kernel6.18-develUpgrade kernel6.18-debuginfo-common-x86_64Upgrade perf6.18Upgrade python3-perf6.18Upgrade perf6.18-debuginfoUpgrade kernel6.18-debuginfo-common-aarch64 | Sep 30, 2026 | Aug 22, 2026 |
| Debian | — | Upgrade linuxUpgrade linux-6.12 | Aug 26, 2026 | Aug 26, 2026 |
| Redhat_linux | — | No solution exists | Aug 26, 2026 | Aug 22, 2026 |
| Ubuntu | — | Upgrade linux-image-5.15.0-1112-intel-iotgUpgrade linux-image-azure-fdeUpgrade linux-image-kvmUpgrade linux-image-5.15.0-1100-gkeopUpgrade linux-image-5.15.0-1118-gcpUpgrade linux-image-azureUpgrade linux-image-lowlatencyUpgrade linux-image-lowlatency-hwe-20.04Upgrade linux-image-lowlatency-64k-hwe-20.04Upgrade linux-image-5.15.0-1109-intel-iot-realtimeUpgrade linux-image-generic-5.15Upgrade linux-image-aws-64k-5.15Upgrade linux-image-5.15.0-195-lowlatency-64kUpgrade linux-image-gcp-5.15Upgrade linux-image-gke-5.15Upgrade linux-image-generic-64k-hwe-20.04Upgrade linux-image-azure-fde-5.15Upgrade linux-image-awsUpgrade linux-image-5.15.0-1117-awsUpgrade linux-image-5.15.0-1122-azure-fdeUpgrade linux-image-intel-iot-realtime-5.15Upgrade linux-image-azure-fipsUpgrade linux-image-5.15.0-1113-gkeUpgrade linux-image-generic-64k-5.15Upgrade linux-image-gcp-fips-5.15Upgrade linux-image-oem-20.04dUpgrade linux-image-azure-cvmUpgrade linux-image-aws-lts-22.04Upgrade linux-image-gcp-fipsUpgrade linux-image-5.15.0-1123-azure-fipsUpgrade linux-image-ibmUpgrade linux-image-aws-fips-5.15Upgrade linux-image-oracle-5.15Upgrade linux-image-virtual-hwe-20.04Upgrade linux-image-5.15.0-1117-aws-fipsUpgrade linux-image-oem-20.04cUpgrade linux-image-lowlatency-5.15Upgrade linux-image-intel-iotg-5.15Upgrade linux-image-azure-fips-5.15Upgrade linux-image-5.15.0-198-genericUpgrade linux-image-5.15.0-198-fipsUpgrade linux-image-5.15.0-195-lowlatencyUpgrade linux-image-5.15.0-1080-xilinx-zynqmpUpgrade linux-image-lowlatency-64k-5.15Upgrade linux-image-kvm-5.15Upgrade linux-image-generic-lpae-5.15Upgrade linux-image-realtime-5.15Upgrade linux-image-gcpUpgrade linux-image-5.15.0-1117-aws-64kUpgrade linux-image-lowlatency-64kUpgrade linux-image-ibm-5.15Upgrade linux-image-gkeop-5.15Upgrade linux-image-generic-64kUpgrade linux-image-fipsUpgrade linux-image-azure-5.15Upgrade linux-image-5.15.0-198-generic-64kUpgrade linux-image-5.15.0-1109-kvmUpgrade linux-image-oem-20.04Upgrade linux-image-xilinx-zynqmp-5.15Upgrade linux-image-5.15.0-1114-oracleUpgrade linux-image-virtualUpgrade linux-image-oem-20.04bUpgrade linux-image-intel-iotgUpgrade linux-image-genericUpgrade linux-image-gcp-lts-22.04Upgrade linux-image-generic-hwe-20.04Upgrade linux-image-virtual-5.15Upgrade linux-image-xilinx-zynqmpUpgrade linux-image-5.15.0-1111-ibmUpgrade linux-image-fips-5.15Upgrade linux-image-gkeopUpgrade linux-image-generic-lpae-hwe-20.04Upgrade linux-image-azure-lts-22.04Upgrade linux-image-realtimeUpgrade linux-image-gkeUpgrade linux-image-5.15.0-1118-gcp-fipsUpgrade linux-image-5.15.0-198-generic-lpaeUpgrade linux-image-5.15.0-1123-azureUpgrade linux-image-aws-fipsUpgrade linux-image-intel-iot-realtimeUpgrade linux-image-intelUpgrade linux-image-aws-5.15Upgrade linux-image-5.15.0-1116-realtimeUpgrade linux-image-oracleUpgrade linux-image-oracle-lts-22.04Upgrade linux-image-generic-lpaeUpgrade linux-image-aws-64k-lts-22.04 | Oct 6, 2026 | Oct 6, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Aug 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub