{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53259","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.394Z","datePublished":"2026-06-25T08:39:48.571Z","dateUpdated":"2026-08-05T12:34:37.940Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:34:37.940Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: anycast: insert aca into global hash under idev->lock\n\nsyzbot reported a splat [1]: a slab-use-after-free in\nipv6_chk_acast_addr(), which walks the global inet6_acaddr_lst[] hash\nunder RCU and dereferences a struct ifacaddr6 that has already been\nfreed while still linked in the hash, so a later reader walks into a\ndangling node.\n\nIn __ipv6_dev_ac_inc() the aca is allocated with refcount 1, then\naca_get() bumps it to 2 to keep it alive across the unlocked region.\nIt is published to idev->ac_list under idev->lock, but\nipv6_add_acaddr_hash() runs after write_unlock_bh(). A concurrent\nteardown (ipv6_ac_destroy_dev() from addrconf_ifdown(), under RTNL)\ncan slip into that window:\n\n  CPU0 __ipv6_dev_ac_inc           CPU1 ipv6_ac_destroy_dev (RTNL)\n  ------------------------------   ------------------------------------\n  aca_alloc()              refcnt 1\n  aca_get()               refcnt 2\n  write_lock_bh(idev->lock)\n    add aca to ac_list\n  write_unlock_bh(idev->lock)\n                                   write_lock_bh(idev->lock)\n                                     pull aca off ac_list\n                                   write_unlock_bh(idev->lock)\n                                   ipv6_del_acaddr_hash(aca)\n                                     hlist_del_init_rcu() is a no-op,\n                                     aca is not in the hash yet\n                                   aca_put()           refcnt 2->1\n  ipv6_add_acaddr_hash(aca)\n    aca now inserted into the hash\n  aca_put()                refcnt 1->0\n    call_rcu(aca_free_rcu) -> kfree(aca)\n\nThe hash removal becomes a no-op because the insertion has not\nhappened yet, so once CPU0 inserts and drops the last reference, the\naca is freed while still linked in inet6_acaddr_lst[], and readers\ndereference freed memory after the slab slot is reused.\n\nThis window opened once RTNL stopped serializing the join path against\ndevice teardown. Move ipv6_add_acaddr_hash() inside the idev->lock\nsection so the ac_list and hash insertions are atomic with respect to\nteardown: a racing remover now either misses the aca entirely or finds\nit in both lists.\n\nacaddr_hash_lock is now nested under idev->lock, which is acquired in\nsoftirq context, so switch all acaddr_hash_lock sites to spin_lock_bh()\nto avoid the irq lock inversion reported in [2].\n\n[1] https://syzkaller.appspot.com/bug?extid=a01df04303c131efbf3a\n[2] https://lore.kernel.org/netdev/6a194ef7.ba3b1513.1890b4.0000.GAE@google.com/"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable anycast insertion path is reached through local IPv6 socket configuration such as setsockopt(IPV6_JOIN_ANYCAST), with teardown driven by local netdevice unregister/down paths. Remote packets can hit a later reader, but an attacker must first locally create the dangling anycast object.\nAC:L - The bug is a race between anycast join and device teardown, and a local attacker with net namespace control can drive both sides concurrently and retry. No rare external condition is required beyond winning an attacker-created race.\nPR:L - The join path checks CAP_NET_ADMIN in net->user_ns, which is reachable by an unprivileged user in a user/network namespace on systems permitting unprivileged user namespaces. It does not require real init-namespace root in the highest reasonable scenario.\nUI:N - Exploitation does not require a victim user to open a file, mount a filesystem, or perform any action. The attacker can invoke the socket option and teardown paths directly.\nS:U - The impact is within the kernel/network namespace security authority and does not cross a VM, IOMMU, or separate trust boundary. Kernel privilege escalation or kernel crash is scored as unchanged scope.\nC:H - This is a slab use-after-free where a freed ifacaddr6 remains linked in the global anycast hash and later readers dereference reused heap contents including pointers. Per kernel UAF guidance and the dangling global pointer primitive, high confidentiality impact is appropriate.\nI:H - A kernel use-after-free with attacker-influenced heap reuse can potentially be shaped into memory corruption or control-flow/data corruption primitives. When uncertain for UAF exploitability, the higher severity integrity impact is selected.\nA:H - syzbot reported a KASAN slab-use-after-free in ipv6_chk_acast_addr, and dereferencing the stale object can crash/oops the kernel. This is high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/anycast.c"],"versions":[{"version":"eb1ac9ff6c4a5720b1a1476233be374c5dc44bff","lessThan":"15be7e9fdbff831fb3e89b83cc337a4f85ad3310","status":"affected","versionType":"git"},{"version":"eb1ac9ff6c4a5720b1a1476233be374c5dc44bff","lessThan":"3a967c498baa976b11d4800dda224c507416e97c","status":"affected","versionType":"git"},{"version":"eb1ac9ff6c4a5720b1a1476233be374c5dc44bff","lessThan":"f723ccaff2fb72b71ae8a9fd283f0dee4d9ae7a3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/anycast.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.18.36","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.13","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.36"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.0.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/15be7e9fdbff831fb3e89b83cc337a4f85ad3310"},{"url":"https://git.kernel.org/stable/c/3a967c498baa976b11d4800dda224c507416e97c"},{"url":"https://git.kernel.org/stable/c/f723ccaff2fb72b71ae8a9fd283f0dee4d9ae7a3"}],"title":"ipv6: anycast: insert aca into global hash under idev->lock","x_generator":{"engine":"bippy-1.2.0"}}}}