{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.176-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.86-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels  seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking dst_hold() unconditionally. On PREEMPT_RT, ksoftirqd is preemptible and a higher-priority task can release the underlying pcpu_rt between the lookup and the caching through a concurrent FIB lookup on a shared nexthop. Simplified race sequence:    ksoftirqd/X                       higher-prio task (same CPU X)   -----------                       --------------------------------   seg6_input_core(,skb)/rpl_input(skb)     dst_cache_get()       -\u003e miss     ip6_route_input(skb)       -\u003e ip6_pol_route(,skb,flags)          [RT6_LOOKUP_F_DST_NOREF in flags]         -\u003e FIB lookup resolves fib6_nh            [nhid=N route]         -\u003e rt6_make_pcpu_route()            [creates pcpu_rt, refcount=1]              pcpu_rt-\u003esernum = fib6_sernum              [fib6_sernum=W]            -\u003e cmpxchg(fib6_nh.rt6i_pcpu,                       NULL, pcpu_rt)               [slot was empty, store succeeds]       -\u003e skb_dst_set_noref(skb, dst)          [dst is pcpu_rt, refcount still 1]                                      rt_genid_bump_ipv6()                                       -\u003e bumps fib6_sernum                                          [fib6_sernum from W to Z]                                     ip6_route_output()                                       -\u003e ip6_pol_route()                                         -\u003e FIB lookup resolves fib6_nh                                            [nhid=N]                                         -\u003e rt6_get_pcpu_route()                                              pcpu_rt-\u003esernum != fib6_sernum                                              [W \u003c\u003e Z, stale]                                           -\u003e prev = xchg(rt6i_pcpu, NULL)                                           -\u003e dst_release(prev)                                              [prev is pcpu_rt,                                               refcount 1-\u003e0, dead]      dst = skb_dst(skb)     [dst is the dead pcpu_rt]     dst_cache_set_ip6(dst)       -\u003e dst_hold() on dead dst       -\u003e WARN / use-after-free  For the race to occur, ksoftirqd must be preemptible (PREEMPT_RT without PREEMPT_RT_NEEDS_BH_LOCK) and a concurrent task must be able to release the pcpu_rt. Shared nexthop objects provide such a path, as two routes pointing to the same nhid share the same fib6_nh and its rt6i_pcpu entry.  Fix seg6_input_core() and rpl_input() by calling skb_dst_force() after ip6_route_input() to force the NOREF dst into a refcounted one before caching. The output path is not affected as ip6_route_output() already returns a refcounted dst.",
  "id": "DEBIAN-CVE-2026-46099",
  "modified": "2026-09-10T08:47:30.430374806Z",
  "published": "2026-05-27T14:17:31.557Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-46099"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-46099"
  ]
}