CVE-2026-90111: ip6mr: do not clone dst in ip6mr_cache_report()
In the Linux kernel, the following vulnerability has been resolved:
ip6mr: do not clone dst in ip6mrcachereport()
IPv6 input attaches a non-refcounted (NOREF) dst to skbs under RCU. When an ingress multicast packet misses MFC lookup, ip6mrcacheunresolved() places the skb onto the unresolved queue, escaping the receive-side RCU grace period.
If the underlying route is deleted and freed, and the MFC queue is later resolved with a wrong parent interface, ip6mrforward() invokes ip6mrcachereport(..., MRT6MSGWRONGMIF), which executes dstclone(skbdst(pkt)) on the freed dst entry, triggering a slab use-after-free.
Report packets queued to mroute6sk (a raw socket) and netlink notifications do not require an attached dst entry.
Fix this by: 1. Removing dstclone() in ip6mrcachereport() and ensuring report skbs do not hold a dst. 2. Dropping skbdst before queuing unresolved skbs in ip6mrcacheunresolved(), matching the fact that multicast forwarding resolves outgoing routes anew via ip6routeoutput().