Answer in brief
CVE-2026-89555 records a Unknown severity vulnerability in mpls: reload header after pskb_may_pull(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=9f427a0e474a67b454420c131709600d44850486 <fed638a248116b8a249bd4202d28e5934bdc65ad || >=9f427a0e474a67b454420c131709600d44850486 <d82b90a38c2ca8a0694428eab0e9551c23f2447d || >=9f427a0e474a67b454420c131709600d44850486 <49d38c1b4390412f8950d33dfaee0ccbd17beb81 || >=9f427a0e474a67b454420c131709600d44850486 <29e63b8d9fc150cc191b1c6eb7e16e1247e1b650 || ad864d9fce0ec56cc8f6afe5c6a0e6d7f484b9eb || >=4.9.8 <4.10 | fed638a248116b8a249bd4202d28e5934bdc65ad, d82b90a38c2ca8a0694428eab0e9551c23f2447d, 49d38c1b4390412f8950d33dfaee0ccbd17beb81, 29e63b8d9fc150cc191b1c6eb7e16e1247e1b650, 4.10 |
| Linux/Linuxgeneric | 4.10 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: mpls: reload header after pskb_may_pull() mpls_select_multipath() calls mpls_multipath_hash() to choose a nexthop when an MPLS route has multiple nexthops. While walking the MPLS label stack, the hash routine caches hdr for the current label. After finding the bottom-of-stack label, it calls pskb_may_pull() before reading the inner IP header. If an skb is constructed with the inner IP header in nonlinear data and insufficient tailroom in the linear head, pskb_may_pull() calls pskb_expand_head() to replace the skb head and free the old one. This leaves hdr pointing to freed memory. The IPv6 path can invalidate hdr again when it performs a second pull for the larger header. The issue was found through static analysis. A reproducer sending a legal Geneve packet through a bareudp/MPLS multipath setup triggered the same KASAN report in 2 of 2 unpatched runs: BUG: KASAN: slab-use-after-free in mpls_select_multipath Read of size 1 at addr ffff88800ecc6e20 by task ksoftirqd/1/23 Call Trace: mpls_select_multipath mpls_forward __netif_receive_skb_list_core netif_receive_skb_list_internal napi_complete_done gro_cell_poll __napi_poll net_rx_action Freed by task 23: kfree pskb_expand_head __pskb_pull_tail mpls_select_multipath Reload hdr from the current skb head after each successful pull before deriving the inner IPv4 or IPv6 header pointer.
Quoted source text, attributed separately from HOL analysis.