CVE-2026-46099 is a use-after-free vulnerability in Linux kernel IPv6 Segment Routing (seg6) and RPL lightweight tunnel input processing. The seg6_input_core() and rpl_input() functions call ip6_route_input(), which attaches a non-reference-counted (NOREF) destination to the socket buffer, then pass that destination to dst_cache_set_ip6(), which unconditionally invokes dst_hold(). On PREEMPT_RT configurations without PREEMPT_RT_NEEDS_BH_LOCK, a higher-priority task can preempt ksoftirqd and release the underlying per-CPU route through a concurrent IPv6 FIB lookup on a shared nexthop. The input path subsequently attempts to acquire a reference to the freed destination, triggering a kernel warning or use-after-free. The IPv6 output path is unaffected because ip6_route_output() already returns a reference-counted destination.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A use-after-free race in Linux kernel IPv6 SEG6 and RPL lightweight tunnels. On PREEMPT_RT configurations without PREEMPT_RT_NEEDS_BH_LOCK, a higher-priority task can release a shared per-CPU route while an input-path task holds an unreferenced destination pointer, causing caching to access a freed object. The output path is unaffected. The advisory rates the vulnerability High, with a CVSS v3 score of 7.3, and recommends updating Echo linux packages to version 6.1.176-1 or later.
A Linux kernel IPv6 issue involving NOREF destination use in SEG6 and RPL lightweight tunnels, affecting Rocky Linux 10.2 kernel packages.
Linux kernel IPv6 flaw involving NOREF destination usage in SRv6 and RPL lightweight tunnels.
A vulnerability affecting the Red Hat Enterprise Linux 10 kernel package set; no technical flaw details are provided in the content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.