Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93226— ipv6: use RCU iterator to dump route exceptions

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到解决: ipv6: 使用 RCU 迭代器转储路由异常 使用 遍历受 RCU 保护的异常列表。调用者持有 ,但未持有 ,因此 可能并发地通过 添加条目。 KCSAN 报告了此竞态条件(无关细节已省略): 使用 安全地遍历异常列表。

AI Predicted 6.5 Difficulty: Hard EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1057 · Process Discovery

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9< dffbfb3117138e8e0e09d05f507bd36ca1f696e5 affected
1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9< 6bd3f94ed858f2d072627546b4cdf712b0f8ea88 affected
1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9< 9c6be625e1a7258e845d6193b3b6b084a00f8e9e affected
1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9< 3665abc3d2ae8a78cb67f858e848481432ec75db affected
1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9< eda56ee17713f9dd834b922f7dbfa2e25fa6358c affected
1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9< a602cd128d17a793e12888edc8eda85821ede7e1 affected
1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9< f6b1b15848fd91fe122dac0d19d3d666e35075b6 affected
1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9< 47cdab0d51aaa9bd85f8e4904585bd5bd4df4488 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93226

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ipv6: use RCU iterator to dump route exceptions
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU iterator to dump route exceptions rt6_nh_dump_exceptions() uses hlist_for_each_entry() to iterate over RCU-protected exception lists. The caller holds rcu_read_lock(), but does not hold rt6_exception_lock, so rt6_insert_exception() can concurrently add an entry with hlist_add_head_rcu(). KCSAN reports this race (irrelevant details omitted): ================================================================== BUG: KCSAN: data-race in rt6_insert_exception / rt6_nh_dump_exceptions write (marked) to 0xffff8a7c44c59620 of 8 bytes by interrupt on cpu 5: rt6_insert_exception+0x3bb/0x760 __ip6_rt_update_pmtu+0x4fe/0x750 ip6_sk_update_pmtu+0x19a/0x3b0 udpv6_err+0x3ff/0x800 icmpv6_notify+0x1e1/0x440 icmpv6_rcv+0x8c0/0xab0 ip6_protocol_deliver_rcu+0x616/0x840 ip6_input_finish+0xb9/0x160 ... entry_SYSCALL_64_after_hwframe+0x77/0x7f read to 0xffff8a7c44c59620 of 8 bytes by task 549 on cpu 14: rt6_nh_dump_exceptions+0xb3/0x260 rt6_dump_route+0x53e/0x5f0 fib6_dump_node+0x6d/0xf0 fib6_walk_continue+0x290/0x2d0 fib6_dump_table+0x28d/0x360 inet6_dump_fib+0x37d/0x620 rtnl_dumpit+0x7b/0xd0 netlink_dump+0x3ae/0x7e0 ... entry_SYSCALL_64_after_hwframe+0x77/0x7f 4 locks held by dumper/549: ... #1: (rcu_read_lock){....}-{1:3}, at: inet6_dump_fib+0x88/0x620 #2: (&tb->tb6_lock){+.-.}-{3:3}, at: fib6_dump_table+0x1e9/0x360 #3: (rcu_read_lock){....}-{1:3}, at: rt6_dump_route+0x483/0x5f0 value changed: 0xffff8a7c44e05700 -> 0xffff8a7c45d60100 Reported by Kernel Concurrency Sanitizer on: CPU: 14 UID: 0 PID: 549 Comm: dumper Not tainted 7.2.0-rc7-virtme #38 PREEMPT(lazy) ... Use hlist_for_each_entry_rcu() to safely iterate over the exception list.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 ~ dffbfb3117138e8e0e09d05f507bd36ca1f696e5 -
Linux Linux 5.3 -

II. Public POCs for CVE-2026-93226

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93226

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93226 (8)

Same Patch Batch · Linux · 2026-09-24 · 234 CVEs total

CVE-2026-93207 9.8 CRITICAL SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
CVE-2026-97413 9.8 CRITICAL RDMA/rtrs-srv: Fix integer underflow in process_read and process_write
CVE-2026-93228 9.1 CRITICAL svcrdma: Reject Write/Reply chunks with segcount 0
CVE-2026-93793 8.8 HIGH wifi: iwlwifi: mvm: validate TX_CMD response layout
CVE-2026-93799 8.8 HIGH wifi: iwlwifi: mvm: validate sta_id in BA window status notif
CVE-2026-93790 8.8 HIGH wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif
CVE-2026-93806 8.8 HIGH wifi: cfg80211: validate assoc response length before status and IE access
CVE-2026-97442 8.8 HIGH wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
CVE-2026-97409 8.8 HIGH nvme-fc: Do not cancel requests in io target before it is initialized
CVE-2026-97509 8.8 HIGH thunderbolt: Keep XDomain reference during the lifetime of a service
CVE-2026-93280 8.8 HIGH greybus: audio: bound the topology section sizes against the fetched size
CVE-2026-93284 8.8 HIGH drm/pagemap: dma-unmap pages before handling migration errors
CVE-2026-97451 8.4 HIGH ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)
CVE-2026-97452 8.4 HIGH ACPICA: Prevent adding invalid references
CVE-2026-97455 8.4 HIGH ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()
CVE-2026-97450 8.4 HIGH ACPICA: validate handler object type in two places
CVE-2026-93827 8.4 HIGH virtio-fs: avoid double-free on failed queue setup
CVE-2026-97433 8.2 HIGH nvme: validate FDP configuration descriptor sizes
CVE-2026-93221 8.1 HIGH nfsd: convert nfsd_net boolean flags to unsigned long flags word
CVE-2026-93786 8.1 HIGH ksmbd: preserve VFS inherited POSIX ACL mask

Showing top 20 of 234 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93226

No comments yet


Leave a comment