{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89555","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.724Z","datePublished":"2026-09-11T19:44:28.331Z","dateUpdated":"2026-09-14T12:00:57.921Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:57.921Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: reload header after pskb_may_pull()\n\nmpls_select_multipath() calls mpls_multipath_hash() to choose a nexthop\nwhen an MPLS route has multiple nexthops.  While walking the MPLS label\nstack, the hash routine caches hdr for the current label.  After finding\nthe bottom-of-stack label, it calls pskb_may_pull() before reading the\ninner IP header.\n\nIf an skb is constructed with the inner IP header in nonlinear data and\ninsufficient tailroom in the linear head, pskb_may_pull() calls\npskb_expand_head() to replace the skb head and free the old one.  This\nleaves hdr pointing to freed memory.  The IPv6 path can invalidate hdr\nagain when it performs a second pull for the larger header.\n\nThe issue was found through static analysis.  A reproducer sending a legal\nGeneve packet through a bareudp/MPLS multipath setup triggered the same\nKASAN report in 2 of 2 unpatched runs:\n\n  BUG: KASAN: slab-use-after-free in mpls_select_multipath\n  Read of size 1 at addr ffff88800ecc6e20 by task ksoftirqd/1/23\n\n  Call Trace:\n   mpls_select_multipath\n   mpls_forward\n   __netif_receive_skb_list_core\n   netif_receive_skb_list_internal\n   napi_complete_done\n   gro_cell_poll\n   __napi_poll\n   net_rx_action\n\n  Freed by task 23:\n   kfree\n   pskb_expand_head\n   __pskb_pull_tail\n   mpls_select_multipath\n\nReload hdr from the current skb head after each successful pull before\nderiving the inner IPv4 or IPv6 header pointer."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - mpls_forward() is the ETH_P_MPLS_UC packet_type receive handler; remote MPLS-in-IP (IPPROTO_MPLS), MPLS-over-UDP/bareudp, Geneve, and IPIP/SIT/ip6 tunnels deliver inner MPLS into this path without local access, matching the Geneve/bareudp KASAN reproducer.\nAC:L - An attacker sending MPLS or tunneled overlay frames fully controls the label stack, BOS bit, and skb layout; GRO/tunnel decap yields nonlinear skbs so pskb_may_pull() reallocates skb->head, and the unpatched Geneve reproducer hit the UAF in 2 of 2 runs with no victim-timed race.\nPR:N - Exploitation needs only unauthenticated packets that hit an already configured MPLS-enabled interface and multipath label route; mpls_forward() performs no credential check, and enabling MPLS input or tunnels is victim deployment rather than an attacker privilege.\nUI:N - The use-after-free runs in softirq receive processing (gro_cell_poll / netif_receive_skb_list) as soon as the crafted frame is accepted; no local user or administrator action is required beyond normal forwarding.\nS:U - The stale MPLS header pointer is a heap use-after-free inside the same host kernel MPLS forwarding path; impact stays within that kernel security authority and does not cross a VM, IOMMU, or other boundary.\nC:H - After pskb_expand_head() frees the old skb head, mpls_multipath_hash() reads the inner IPv4/IPv6 header through the stale hdr pointer, a slab use-after-free that can disclose freed kmalloc contents and is scored as high-impact kernel information disclosure.\nI:H - The immediate stale access is a header read used for ECMP hashing, but it remains a kernel slab use-after-free of skb->head; attacker-controlled reclaim of the freed kmalloc object is a well-established path to heap corruption and control-flow hijacking.\nA:H - KASAN confirmed a slab-use-after-free in mpls_select_multipath() on the forwarding path; dereferencing the freed skb head can oops or panic the kernel, and UAFs remain a high-impact denial of service even without full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mpls/af_mpls.c"],"versions":[{"version":"9f427a0e474a67b454420c131709600d44850486","lessThan":"aa4fe0b450a461aa1162fe8375f5d28f4c957df8","status":"affected","versionType":"git"},{"version":"9f427a0e474a67b454420c131709600d44850486","lessThan":"b1c0783b2facc398437ad8f8b86c636d7a78f8db","status":"affected","versionType":"git"},{"version":"9f427a0e474a67b454420c131709600d44850486","lessThan":"bfaaff99238326166694354a63a76c02563f98b1","status":"affected","versionType":"git"},{"version":"9f427a0e474a67b454420c131709600d44850486","lessThan":"d9640239827d6d0cb84263b590f7a4f1596c17eb","status":"affected","versionType":"git"},{"version":"9f427a0e474a67b454420c131709600d44850486","lessThan":"fed638a248116b8a249bd4202d28e5934bdc65ad","status":"affected","versionType":"git"},{"version":"9f427a0e474a67b454420c131709600d44850486","lessThan":"d82b90a38c2ca8a0694428eab0e9551c23f2447d","status":"affected","versionType":"git"},{"version":"9f427a0e474a67b454420c131709600d44850486","lessThan":"49d38c1b4390412f8950d33dfaee0ccbd17beb81","status":"affected","versionType":"git"},{"version":"9f427a0e474a67b454420c131709600d44850486","lessThan":"29e63b8d9fc150cc191b1c6eb7e16e1247e1b650","status":"affected","versionType":"git"},{"version":"ad864d9fce0ec56cc8f6afe5c6a0e6d7f484b9eb","status":"affected","versionType":"git"},{"version":"4.9.8","lessThan":"4.10","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mpls/af_mpls.c"],"versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/aa4fe0b450a461aa1162fe8375f5d28f4c957df8"},{"url":"https://git.kernel.org/stable/c/b1c0783b2facc398437ad8f8b86c636d7a78f8db"},{"url":"https://git.kernel.org/stable/c/bfaaff99238326166694354a63a76c02563f98b1"},{"url":"https://git.kernel.org/stable/c/d9640239827d6d0cb84263b590f7a4f1596c17eb"},{"url":"https://git.kernel.org/stable/c/fed638a248116b8a249bd4202d28e5934bdc65ad"},{"url":"https://git.kernel.org/stable/c/d82b90a38c2ca8a0694428eab0e9551c23f2447d"},{"url":"https://git.kernel.org/stable/c/49d38c1b4390412f8950d33dfaee0ccbd17beb81"},{"url":"https://git.kernel.org/stable/c/29e63b8d9fc150cc191b1c6eb7e16e1247e1b650"}],"title":"mpls: reload header after pskb_may_pull()","x_generator":{"engine":"bippy-1.2.0"}}}}