CVE-2026-89783

Source
https://cve.org/CVERecord?id=CVE-2026-89783
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89783.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89783
Downstream
Published
2026-09-16T08:48:21Z
Modified
2026-09-17T03:47:07Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
Details

In the Linux kernel, the following vulnerability has been resolved:

xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full

The depth check in xfrm6_input_addr() is off by one:

if (1 + sp->len == XFRM_MAX_DEPTH) goto drop; ... sp->xvec[sp->len++] = x;

xfrm_input() can leave sp->len == XFRM_MAX_DEPTH, and the transport-mode receive path re-enters IPv6 input via xfrm_trans_reinject() with that secpath preserved. If the inner packet carries a destination-options HAO option or a type-2 routing header, xfrm6_input_addr() is called with sp->len == XFRM_MAX_DEPTH; the check (1 + 6 == 6) is false, so sp->xvec[sp->len++] writes one slot past the 6-element xvec[]. The write stays within the sec_path allocation (invisible to KASAN); UBSAN_BOUNDS flags it and panics under panic_on_warn.

Use "sp->len >= XFRM_MAX_DEPTH", matching xfrm_input(). This also restores one chain level the old check rejected at sp->len == 5.

UBSAN: array-index-out-of-bounds in net/ipv6/xfrm6_input.c:309:10 index 6 is out of range for type 'xfrm_state *[6]'

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89783.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9473e1f631de339c50bde1e3bd09e1045fe90fd5
Fixed
91fc387f63c00ddfb5221127a17bac97549a8343
Fixed
68e8737fe8e72f085c608cff322b3d2de8340af1
Fixed
8fe2c53fb81f5ad5be43af2ad09583f7c78b4b77
Fixed
bdcda866c89f9a8b1acdabf02d26cde9fbe501d8
Fixed
48996649222e95008cdb98cd58579e3fc8e5ee06
Fixed
0f679e0523ddfff3fb554336ceb874b0e51e9cd3
Fixed
5f35a29a5eed3d80befd32050843ac88dea3d61a
Fixed
5d9e3bf34fec9a5d237e4b7cef4a707bc2e091bc

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89783.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.25
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89783.json"