{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74597","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.919Z","datePublished":"2026-08-22T15:31:47.120Z","dateUpdated":"2026-08-25T05:40:23.709Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-25T05:40:23.709Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: clear skb2->cb[] in ip6ip6_err()\n\nip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the\nquoted inner IPv6 packet, and then passes the clone to icmpv6_send().\nThe clone still carries the outer packet's inet6_skb_parm in skb->cb.\n\nIf the outer packet had a Home Address Option, IP6CB(skb2)->dsthao\nremains non-zero after skb_pull(). icmpv6_send() later calls\nmip6_addr_swap(), which uses that stale dsthao offset against the quoted\ninner packet. A malformed inner destination-options header can then make\nthe HAO lookup and address swap run past the end of the quoted packet\nand corrupt skb_shared_info.\n\nClear skb2->cb[] before pulling the quoted inner IPv6 packet so the\nreply path does not reuse metadata left by the outer IPv6 stack."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug is reached when a remote peer sends a forged ICMPv6 error whose quoted payload is an IPv6-in-IPv6 tunnel datagram; processing follows the normal IPv6 receive path (ipv6_rcv -> icmpv6_notify -> tunnel6_err -> ip6ip6_err) with no local access required.\nAC:L - The attacker controls the carrier IPv6 Home Address Option, quoted tunnel/inner headers, and ICMP error type; once an ip6tnl endpoint exists (normal for this subsystem), triggering the stale-dsthao path is reliable and needs no races or victim interaction.\nPR:N - No authentication or capabilities are required on the target; unprivileged remote senders can deliver crafted ICMPv6 errors that the kernel processes on the standard pre-auth receive path (INET6_PROTO_NOPOLICY).\nUI:N - Exploitation requires only delivering a malicious network packet; no victim must open files, click links, or perform any other action.\nS:U - Impact is in-kernel memory corruption on the receiving host within the same security authority; it does not by itself cross VM, container, or IOMMU boundaries.\nC:H - With CONFIG_IPV6_MIP6, mip6_addr_swap() uses the stale dsthao offset to scan the quoted inner packet and can read attacker-controlled bytes past the skb tail while resolving a fake HAO TLV before swapping addresses.\nI:H - The resulting 16-byte swap(iph->saddr, hao->addr) can write beyond the quoted packet into skb_shared_info, giving attacker-influenced heap corruption suitable for further control-flow or data manipulation.\nA:H - Corrupting skb_shared_info from the network input path can cause kernel oops/panic or otherwise deny service on IPv6 tunnel endpoints, and the condition is repeatable with crafted packets."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/ip6_tunnel.c"],"versions":[{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"44fe898df302e91c5ee5acbc71ffa74e78e6c183","status":"affected","versionType":"git"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"0dadb0620ab65949a8bc2439dd28ea3c942fe87d","status":"affected","versionType":"git"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"b6816536a2990c0db44a26130a03e40b441e829b","status":"affected","versionType":"git"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"64e41736a26f37ab6215bc2e6df125df05aceb08","status":"affected","versionType":"git"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"484134e1eb07d700a73b1e4bbf3fb503e299be60","status":"affected","versionType":"git"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"4eb15c465337b18f44716c499cd6ad63eee0ad54","status":"affected","versionType":"git"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"fbf40faa0414b753212494ad197542002e66ed9e","status":"affected","versionType":"git"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"f803c086399da277b5d0ff36a107d0f162751800","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/ip6_tunnel.c"],"versions":[{"version":"2.6.22","status":"affected"},{"version":"0","lessThan":"2.6.22","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"6.6.152"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"6.12.104"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"6.18.45"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"7.1.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/44fe898df302e91c5ee5acbc71ffa74e78e6c183"},{"url":"https://git.kernel.org/stable/c/0dadb0620ab65949a8bc2439dd28ea3c942fe87d"},{"url":"https://git.kernel.org/stable/c/b6816536a2990c0db44a26130a03e40b441e829b"},{"url":"https://git.kernel.org/stable/c/64e41736a26f37ab6215bc2e6df125df05aceb08"},{"url":"https://git.kernel.org/stable/c/484134e1eb07d700a73b1e4bbf3fb503e299be60"},{"url":"https://git.kernel.org/stable/c/4eb15c465337b18f44716c499cd6ad63eee0ad54"},{"url":"https://git.kernel.org/stable/c/fbf40faa0414b753212494ad197542002e66ed9e"},{"url":"https://git.kernel.org/stable/c/f803c086399da277b5d0ff36a107d0f162751800"}],"title":"ip6_tunnel: clear skb2->cb[] in ip6ip6_err()","x_generator":{"engine":"bippy-1.2.0"}}}}