SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-80844

UNKNOWN · CVSS N/A EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-19

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's AH6 implementation, specifically in how it validates the `segments_left` value in routing headers for raw IPv6 HDRINCL packets. An attacker could exploit this flaw to cause an out-of-bounds memory access, potentially leading to system crashes or arbitrary code execution. Organizations using Linux systems, particularly those handling raw IPv6 traffic, should prioritize addressing this vulnerability to mitigate potential security risks.

CVE
CVE-2026-80844
Severity
UNKNOWN
CVSS
N/A
EPSS
0.19%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets. A packet with hdrlen equal to 2 describes one address, but can carry an arbitrary segments_left value. With segments_left equal to 255, the function moves its address pointer 4,064 bytes backwards and passes a 4,064-byte length to memmove(), resulting in an out-of-bounds access. Validate the invariant locally before modifying the routing header or performing any address-pointer arithmetic, and propagate malformed-header errors to the existing AH6 input and output error paths.