{"cvss":8.1,"datePublished":"2026-05-27T14:17:31.557","dateUpdated":"2026-09-09T13:20:15.450","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels\n\nseg6_input_core() and rpl_input() call ip6_route_input() which sets a\nNOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking\ndst_hold() unconditionally.\nOn PREEMPT_RT, ksoftirqd is preemptible and a higher-priority task can\nrelease the underlying pcpu_rt between the lookup and the caching\nthrough a concurrent FIB lookup on a shared nexthop.\nSimplified race sequence:\n\n  ksoftirqd/X                       higher-prio task (same CPU X)\n  -----------                       --------------------------------\n  seg6_input_core(,skb)/rpl_input(skb)\n    dst_cache_get()\n      -> miss\n    ip6_route_input(skb)\n      -> ip6_pol_route(,skb,flags)\n         [RT6_LOOKUP_F_DST_NOREF in flags]\n        -> FIB lookup resolves fib6_nh\n           [nhid=N route]\n        -> rt6_make_pcpu_route()\n           [creates pcpu_rt, refcount=1]\n             pcpu_rt->sernum = fib6_sernum\n             [fib6_sernum=W]\n           -> cmpxchg(fib6_nh.rt6i_pcpu,\n                      NULL, pcpu_rt)\n              [slot was empty, store succeeds]\n      -> skb_dst_set_noref(skb, dst)\n         [dst is pcpu_rt, refcount still 1]\n\n                                    rt_genid_bump_ipv6()\n                                      -> bumps fib6_sernum\n                                         [fib6_sernum from W to Z]\n                                    ip6_route_output()\n                                      -> ip6_pol_route()\n                                        -> FIB lookup resolves fib6_nh\n                                           [nhid=N]\n                                        -> rt6_get_pcpu_route()\n                                             pcpu_rt->sernum != fib6_sernum\n                                             [W <> Z, stale]\n                                          -> prev = xchg(rt6i_pcpu, NULL)\n                                          -> dst_release(prev)\n                                             [prev is pcpu_rt,\n                                              refcount 1->0, dead]\n\n    dst = skb_dst(skb)\n    [dst is the dead pcpu_rt]\n    dst_cache_set_ip6(dst)\n      -> dst_hold() on dead dst\n      -> WARN / use-after-free\n\nFor the race to occur, ksoftirqd must be preemptible (PREEMPT_RT without\nPREEMPT_RT_NEEDS_BH_LOCK) and a concurrent task must be able to release\nthe pcpu_rt. Shared nexthop objects provide such a path, as two routes\npointing to the same nhid share the same fib6_nh and its rt6i_pcpu\nentry.\n\nFix seg6_input_core() and rpl_input() by calling skb_dst_force() after\nip6_route_input() to force the NOREF dst into a refcounted one before\ncaching.\nThe output path is not affected as ip6_route_output() already returns a\nrefcounted dst.","id":"CVE-2026-46099","raw":{"affected":[{"affectedData":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/ipv6/rpl_iptunnel.c","net/ipv6/seg6_iptunnel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"51fef5a7c4d160839199e941929456ba21ddf73c","status":"affected","version":"af4a2209b1344939eaac11f269c261d347cbc3ee","versionType":"git"},{"lessThan":"b258b849a580285a1692e782ebc902b44c884a71","status":"affected","version":"af4a2209b1344939eaac11f269c261d347cbc3ee","versionType":"git"},{"lessThan":"6bd17925bd6866027a6555db17905b9fc073d38d","status":"affected","version":"af4a2209b1344939eaac11f269c261d347cbc3ee","versionType":"git"},{"lessThan":"52f9db67f8f35f436366cf4980b4f0a2583d0ef0","status":"affected","version":"af4a2209b1344939eaac11f269c261d347cbc3ee","versionType":"git"},{"lessThan":"b778b6d095421619c331fd2d7751143cd5387103","status":"affected","version":"af4a2209b1344939eaac11f269c261d347cbc3ee","versionType":"git"},{"lessThan":"9dd5481f960e337b81d7dfe429529495c1c481c0","status":"affected","version":"af4a2209b1344939eaac11f269c261d347cbc3ee","versionType":"git"},{"lessThan":"f9c52a6ba9780bd27e0bf4c044fd91c13c778b6e","status":"affected","version":"af4a2209b1344939eaac11f269c261d347cbc3ee","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/ipv6/rpl_iptunnel.c","net/ipv6/seg6_iptunnel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.12"},{"lessThan":"4.12","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.209","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.175","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.140","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.86","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.27","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"affectedData":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"defaultStatus":"affected","packageName":"kernel","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:6.12.0-211.39.1.el10_2","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"defaultStatus":"affected","packageName":"kernel","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:6.12.0-55.103.1.el10_0","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:rhel_e4s:9.2"],"defaultStatus":"affected","packageName":"kernel","product":"Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:5.14.0-284.188.1.el9_2","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:rhel_e4s:9.2::nfv"],"defaultStatus":"affected","packageName":"kernel-rt","product":"Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:5.14.0-284.188.1.rt14.473.el9_2","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"defaultStatus":"affected","packageName":"kernel","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:5.14.0-570.138.1.el9_6","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:6"],"defaultStatus":"unaffected","packageName":"kernel","product":"Red Hat Enterprise Linux 6","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"unaffected","packageName":"kernel","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"unaffected","packageName":"kernel-rt","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unaffected","packageName":"kernel","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unaffected","packageName":"kernel-rt","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"affected","packageName":"kernel","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"affected","packageName":"kernel-rt","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"}],"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"6A1605BB-F7DD-4482-A80D-856944C7A446","versionEndExcluding":"5.15.209","versionStartIncluding":"4.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"92385813-D91D-480D-83A1-F423D2CBB2BA","versionEndExcluding":"6.1.175","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"A1A92866-F406-43B5-B2D1-CFC274753E9D","versionEndExcluding":"6.6.140","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"55DA1C62-9991-451E-B8A8-E0004E00F789","versionEndExcluding":"6.12.86","versionStartIncluding":"6.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"A10AC84F-C058-47D5-85B4-E6E51A613B74","versionEndExcluding":"6.18.27","versionStartIncluding":"6.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"CDB78D6D-22C3-4154-B0D0-94AF1CE5C2E3","versionEndExcluding":"7.0.4","versionStartIncluding":"6.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*","matchCriteriaId":"B1EF7059-E670-45F4-B422-54C40FA86390","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels\n\nseg6_input_core() and rpl_input() call ip6_route_input() which sets a\nNOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking\ndst_hold() unconditionally.\nOn PREEMPT_RT, ksoftirqd is preemptible and a higher-priority task can\nrelease the underlying pcpu_rt between the lookup and the caching\nthrough a concurrent FIB lookup on a shared nexthop.\nSimplified race sequence:\n\n  ksoftirqd/X                       higher-prio task (same CPU X)\n  -----------                       --------------------------------\n  seg6_input_core(,skb)/rpl_input(skb)\n    dst_cache_get()\n      -> miss\n    ip6_route_input(skb)\n      -> ip6_pol_route(,skb,flags)\n         [RT6_LOOKUP_F_DST_NOREF in flags]\n        -> FIB lookup resolves fib6_nh\n           [nhid=N route]\n        -> rt6_make_pcpu_route()\n           [creates pcpu_rt, refcount=1]\n             pcpu_rt->sernum = fib6_sernum\n             [fib6_sernum=W]\n           -> cmpxchg(fib6_nh.rt6i_pcpu,\n                      NULL, pcpu_rt)\n              [slot was empty, store succeeds]\n      -> skb_dst_set_noref(skb, dst)\n         [dst is pcpu_rt, refcount still 1]\n\n                                    rt_genid_bump_ipv6()\n                                      -> bumps fib6_sernum\n                                         [fib6_sernum from W to Z]\n                                    ip6_route_output()\n                                      -> ip6_pol_route()\n                                        -> FIB lookup resolves fib6_nh\n                                           [nhid=N]\n                                        -> rt6_get_pcpu_route()\n                                             pcpu_rt->sernum != fib6_sernum\n                                             [W <> Z, stale]\n                                          -> prev = xchg(rt6i_pcpu, NULL)\n                                          -> dst_release(prev)\n                                             [prev is pcpu_rt,\n                                              refcount 1->0, dead]\n\n    dst = skb_dst(skb)\n    [dst is the dead pcpu_rt]\n    dst_cache_set_ip6(dst)\n      -> dst_hold() on dead dst\n      -> WARN / use-after-free\n\nFor the race to occur, ksoftirqd must be preemptible (PREEMPT_RT without\nPREEMPT_RT_NEEDS_BH_LOCK) and a concurrent task must be able to release\nthe pcpu_rt. Shared nexthop objects provide such a path, as two routes\npointing to the same nhid share the same fib6_nh and its rt6i_pcpu\nentry.\n\nFix seg6_input_core() and rpl_input() by calling skb_dst_force() after\nip6_route_input() to force the NOREF dst into a refcounted one before\ncaching.\nThe output path is not affected as ip6_route_output() already returns a\nrefcounted dst."}],"id":"CVE-2026-46099","lastModified":"2026-09-09T13:20:15.450","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":2.2,"impactScore":5.9,"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary"},{"cvssData":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","version":"3.1"},"exploitabilityScore":1.8,"impactScore":5.5,"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]},"published":"2026-05-27T14:17:31.557","references":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/51fef5a7c4d160839199e941929456ba21ddf73c"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/52f9db67f8f35f436366cf4980b4f0a2583d0ef0"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/6bd17925bd6866027a6555db17905b9fc073d38d"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/9dd5481f960e337b81d7dfe429529495c1c481c0"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/b258b849a580285a1692e782ebc902b44c884a71"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/b778b6d095421619c331fd2d7751143cd5387103"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/f9c52a6ba9780bd27e0bf4c044fd91c13c778b6e"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:45114"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:59662"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:59663"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:62568"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:64767"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/errata/RHSA-2026:65712"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://access.redhat.com/security/cve/CVE-2026-46099"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2481972"},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46099.json"}],"sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","vulnStatus":"Modified","weaknesses":[{"description":[{"lang":"en","value":"NVD-CWE-noinfo"}],"source":"nvd@nist.gov","type":"Primary"},{"description":[{"lang":"en","value":"CWE-911"}],"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary"}]},"severity":"HIGH","source":"nvd","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv6: fix NOREF dst use in seg6 and rpl lwt..."}