CVE-2026-80792
N/AIn the Linux kernel, the following vulnerability has been resolved: ipv6: fix use-after-free in ip6_finish_output2() ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmit path or other encapsulation operations within lwtunnel_xmit() can reallocate the skb head, freeing the memory that daddr points to. When lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale daddr pointer to compute the nexthop and to look up or create the neighbour entry. This results in a use-after-free read, which can leak sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or crash the system. Fix this by re-fetching the IPv6 header and the destination address pointer after lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop computation and neighbour lookup operate on valid memory.
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
—EPSS not yet scored
Impact if exploited
—CVSS · not scored
- No impact metrics
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-80792/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-80792/poc.json
References
Technical & other
- https://git.kernel.org/stable/c/75e0a544ebe9af663ef53ca21e9e9185c51fb54a
- https://git.kernel.org/stable/c/c95f01b78266828a57060d754fcbfc92123a98ed
- https://git.kernel.org/stable/c/d960881b9312e781a3429aabceb223ce6b7c882f
- https://git.kernel.org/stable/c/087ee0d914aaae929f1660c9ca878e367655ba1a
- https://git.kernel.org/stable/c/3c770ac4e6f07af7c7b40c474a3efc61ffed7862
- https://git.kernel.org/stable/c/3dc98e5fe82d069dd29b124ffbdb679331dfea43
- https://git.kernel.org/stable/c/99219c82804f266189388e8bf1cf5135d10d5515
- https://git.kernel.org/stable/c/73a187384a8c8b983c7fea046d716b6752a1e7a3
- https://git.kernel.org/stable/c/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e