CVE-2026-46120 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ip6_gre: Use cached t->net in ip6erspan_changelink(). After commit 5e72ce3e3980 ("net: ipv6: Use link netns in newlink() of rtnl_link_ops"), ip6erspan_newlink() correctly resolves the per-netns ip6gre hash via link_net. ip6erspan_changelink() was not converted in that series and still uses dev_net(dev), which diverges from the device's creation netns after IFLA_NET_NS_FD migration. This re-inserts the tunnel into the wrong per-netns hash. The original netns keeps a stale entry. When that netns is later destroyed, ip6gre_exit_rtnl_net() walks the stale entry, producing a slab-use-after-free reported by KASAN, followed by a kernel BUG at net/core/dev.c (LIST_POISON1) in unregister_netdevice_many_notify(). Reachable from an unprivileged user namespace (unshare --user --map-root-user --net). ip6gre_changelink() earlier in the same file already uses the cached t->net; only ip6erspan_changelink() has the wrong shape.
A vulnerability in the Linux kernel's handling of IP6 GRE tunnels can lead to a use-after-free condition. This issue arises in the 'ip6erspan_changelink' function, which incorrectly uses the device's network namespace, diverging from the intended per-namespace hash management. As a result, a stale entry is left in the original namespace, which, when destroyed, causes a use-after-free error detected by KASAN, followed by a kernel bug during network device unregistration. This vulnerability is accessible from an unprivileged user namespace.
Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/01b71ff2857d3598337de11e7840a8e3ff21553c | kernel.org | Patch |
| https://git.kernel.org/stable/c/0fcf6731706f73494245a9c0d64f93bebf95bb51 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1d324c2f43f70c965f25c58cc3611c779adbe47e | kernel.org | Patch |
| https://git.kernel.org/stable/c/311fdd26eb4443d43b909cc67a10f3a5fd1b21b2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7bd0f2b162b426b343a114e1b329f0d8d14fdc6e | kernel.org | Patch |
| https://git.kernel.org/stable/c/cf7fc624329e76c6394653d12353e1d033adea91 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e70cfb40c3a99b232cd42c6a6a10f0d8e039dc82 | kernel.org | Patch |
| https://git.kernel.org/stable/c/eca62bb0569de4d43a4dac06a2092a9d4ca1d702 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.16.12, < 4.17 >= 4.17.1, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.88 >= 6.13, < 6.18.30 >= 6.19, < 7.0.7 4.17 - 4.17 rc7 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 30, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |