Container escape via IPv6 fragmentation bug in Linux kernel

Researcher demonstrated PoC IPV6_FRAG_ESCAPE exploiting a memory-handling flaw in Linux kernel 6.12.x (RHEL/CentOS 10). The vulnerability, now patched but without CVE ID, lets a process inside a container trigger memory corruption and escalate privileges to root on the host.
The attack works in stages: first the improper memory access is triggered, then kernel protection mechanisms are bypassed, allowing the process to modify kernel settings and launch arbitrary code with root rights outside the container boundary.
Vendors
Linux
Products
Centos
Ipv6_Frag_Escape
Linux Kernel
Linux Kernel 6.12.X
Rhel