CVE-2026-80976
Received Received - Intake

Segmentation Fault in Linux Kernel SRv6 Decapsulation

Vulnerability report for CVE-2026-80976, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_and_validate() pulls the outer SRv6 headers and makes the inner packet the skb network header. The IPv6 control block still contains values collected while parsing the outer packet, including nhoff and extension-header flags. End.DX6 and End.DT6 route the inner IPv6 packet directly to the IPv6 input path. An unprivileged user can reach End.DT6 from a user and net namespace by installing a local SID and injecting an outer packet with Hop-by-Hop and Destination Options headers followed by an SRH and a minimal inner IPv6 packet. The outer extension headers leave a large nhoff in IP6CB. After decapsulation, ip6_protocol_deliver_rcu() uses that stale offset on the inner packet and reads beyond the skb head. KASAN reports: BUG: KASAN: slab-out-of-bounds in ip6_protocol_deliver_rcu ip6_protocol_deliver_rcu+0x1118/0x1450 ip6_input_finish+0x11b/0x240 seg6_local_input_core+0xed/0x2e0 lwtunnel_input+0x1e9/0x4e0 ipv6_rthdr_rcv+0x525f/0x6c50 ip6_protocol_deliver_rcu+0xcb7/0x1450 Before clearing IP6CB for an inner IPv6 packet, save its incoming interface index and L3 slave state. Restore both after the clear and set nhoff to the inner IPv6 base-header nexthdr field. Use IP6CB(skb)->iif rather than skb->skb_iif because VRF processing can replace skb_iif with the L3 master while IP6CB keeps the receiving interface. Preserve IP6SKB_L3SLAVE for the same reason.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of IPv6 packets with Segment Routing Header (SRH). When decapsulating outer SRv6 headers, the IPv6 control block retains stale data from the outer packet, including incorrect header offsets. This can cause the kernel to read beyond the packet's memory, leading to a slab-out-of-bounds error and potential crashes.

Detection Guidance

This vulnerability requires kernel-level inspection to detect. Monitor kernel logs for KASAN slab-out-of-bounds errors related to ip6_protocol_deliver_rcu or seg6_local_input_core. Check for crashes or memory corruption in IPv6 packet processing paths.

Impact Analysis

An unprivileged user could exploit this to crash the system by sending maliciously crafted IPv6 packets. This may lead to denial-of-service conditions, system instability, or potential privilege escalation if combined with other vulnerabilities.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a low-level kernel memory corruption issue in the Linux network stack. Compliance impacts would only occur if this vulnerability were exploited to gain unauthorized access to sensitive data or disrupt systems handling regulated data.

Mitigation Strategies

Apply the Linux kernel patch that resets IP6CB after IPv6 decapsulation. Update to a fixed kernel version. Disable SRv6 (Segment Routing IPv6) features if not required. Monitor for unusual IPv6 traffic patterns or crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80976. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart