CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust
In the Linux kernel, the following vulnerability has been resolved:
ila: reload IPv6 header after pskbmaypull in checksum adjust
ilacsumadjusttransport() caches ip6h = ipv6hdr(skb) before calling pskbmaypull(). On a non-linear skb whose transport header sits in a page fragment, pskbmaypull() can call pskbpulltail() / pskbexpandhead() and free the old skb head, leaving ip6h dangling; the following getcsumdiff(ip6h, p) then reads freed memory. ilaupdateipv6locator() uses ip6h (and the iaddr derived from it) again after the csum-adjust call and additionally writes the new locator through that pointer.
Impact: a remote IPv6 packet routed through a configured ILA csum-adjust-transport route or receive-side mapping triggers a slab-use-after-free in ilaupdateipv6locator() (KASAN). The route or mapping requires CAPNETADMIN to configure, but trigger packets are unauthenticated once it exists.
Reload ip6h after each pskbmaypull() in ilacsumadjusttransport() before the csum-diff read. In ilaupdateipv6locator() only the ILACSUMADJUSTTRANSPORT case pulls the skb, so reload ip6h and iaddr in that case alone before the destination-address write; the neutral-map modes never pull and keep their cached pointers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In ila_csum_adjust_transport(), do not reuse cached pointers to ip6h after pskb_may_pull(); reload the IPv6 header (ip6h) after each pskb_may_pull() before continuing with csum-diff reads and locator updates.
Linux kernel (ILA) reload ip6h after pskb_may_pull() in ila_csum_adjust_transport() = implemented
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68127?
CVE-2026-68127 has a risk rating of 48.
How do I fix CVE-2026-68127?
To mitigate CVE-2026-68127, upgrade to the latest version of the Linux kernel where the vulnerability has been patched.
What type of vulnerability is CVE-2026-68127?
CVE-2026-68127 is categorized as a Use After Free vulnerability in the Linux kernel.
What does CVE-2026-68127 affect?
CVE-2026-68127 affects the IPv6 header processing in the Linux kernel.
When was CVE-2026-68127 published?
CVE-2026-68127 was published on August 10, 2026.