Linux Kernel Out-of-Bounds Access Vulnerability in IOAM6 Net Component

Vulnerability

A vulnerability in the Linux kernel's IOAM6 net component can lead to out-of-bounds access in the transmission queue array. This issue arises when a packet is on the reception path, and the queue mapping exceeds the number of available transmission queues, potentially causing memory corruption. The vulnerability has been addressed by adding a check to prevent the index from exceeding the allowed range. Additionally, a missing lock around queue statistics has been added to ensure proper synchronization.

Impact

Exploitation of this vulnerability can lead to out-of-bounds memory access, which may cause memory corruption or undefined behavior in the kernel.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: May 6, 2026, 10:57 AM
Updated: May 6, 2026, 10:57 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.0
remediation
7.7
relevance
7.6
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.