Answer in brief
CVE-2026-97940 records a High severity (CVSS 7.8) vulnerability in ipv6: fix fib6 walker UAF on seq stop. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8d2ca1d7b5c3e63b3a8a81ae99015b615c5f2bf7 <0eede1689610e9eeaf729ba86fd1321799eb91a0 || >=8d2ca1d7b5c3e63b3a8a81ae99015b615c5f2bf7 <b89b691dd00bf39b9ba39ab9446f8c62f419fa7b || >=8d2ca1d7b5c3e63b3a8a81ae99015b615c5f2bf7 <4553cfafa8d05c4ce20b1d18f79d9bb3b303fc02 || >=8d2ca1d7b5c3e63b3a8a81ae99015b615c5f2bf7 <19b4ed644d68098cc62ab612727f40d30f43476c | 0eede1689610e9eeaf729ba86fd1321799eb91a0, b89b691dd00bf39b9ba39ab9446f8c62f419fa7b, 4553cfafa8d05c4ce20b1d18f79d9bb3b303fc02, 19b4ed644d68098cc62ab612727f40d30f43476c |
| Linux/Linuxgeneric | 3.13 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix fib6 walker UAF on seq stop ipv6_route_iter_active() treats a walker in FWS_U at the table root as already unlinked. fib6_del_route() can move a still-linked walker into that same state when the current leaf is the last route at the root, so ipv6_route_native_seq_stop() skips fib6_walker_unlink(). The seq private object can then be freed while it remains on net->ipv6.fib6_walkers. A later route deletion walks the dangling list and uses the freed walker. Use the list head as membership state and reinitialize it when unlinking. Keep the existing w->node check so a never-started iterator with a zeroed private object is not treated as linked. The same stop helper is used by /proc/net/ipv6_route and by the BPF ipv6_route iterator. The BPF show path only widens the race.
Quoted source text, attributed separately from HOL analysis.