Executive brief
A vulnerability was identified in the Linux kernel's IPv6 networking component. The issue occurs when the system processes specific network configuration changes, potentially leading to a system crash (kernel oops). This could result in a denial-of-service, impacting the availability of the affected server or device.
Technical details
A null pointer dereference exists in the fib6_nh_mtu_change() function within net/ipv6/route.c. The vulnerability is caused by an unguarded re-fetch of the 'idev' pointer via __in6_dev_get(arg->dev). During an interface shutdown (addrconf_ifdown), the dev->ip6_ptr can be cleared while a Router Advertisement (RA)-driven MTU update walk is still in progress. Because nexthop-backed routes can survive the initial flush, the walk may attempt to dereference a NULL idev pointer, resulting in a general protection fault. The fix introduces a NULL check to safely return 0 if the device pointer has been cleared.
Affected products
- Linux Linux Kernel c0b220cf7d80 to 46c3b8191aad (mainline)
Timeline
- 2026-06-18: disclosed: Initial patch authored
- 2026-06-22: patched: Patch merged into mainline kernel
- 2026-07-27: advisory: CVE published to NVD
References
- https://git.kernel.org/stable/c/1451deca9896957159f0666520a792c1b861af4f
- https://git.kernel.org/stable/c/302d57ed7872838b40e56a868fb4c7da7da606e9
- https://git.kernel.org/stable/c/46c3b8191aad3d032776bf3bebf03efdf5f4b905
- https://git.kernel.org/stable/c/6428634f7a0b7878144b4925c37856bef3224967
- https://git.kernel.org/stable/c/80600b5d0f3ecb9324120dc95b5e915130f516c5
- https://git.kernel.org/stable/c/b0d0eb13a0441a8ebf4f227843deaf494f1e2c33
- https://git.kernel.org/stable/c/b2c70dd3326809429b709a9c7e9220d29923051a