Junglewise Threat Intelligence

CVE-2026-64538: Linux Kernel null pointer dereference in fib6_nh_mtu_change

CVE-2026-64538 · Severity: info · CVSS 6.2 · Published 2026-07-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's IPv6 networking component. The issue occurs when the system processes specific network configuration changes, potentially leading to a system crash (kernel oops). This could result in a denial-of-service, impacting the availability of the affected server or device.

Technical details

A null pointer dereference exists in the fib6_nh_mtu_change() function within net/ipv6/route.c. The vulnerability is caused by an unguarded re-fetch of the 'idev' pointer via __in6_dev_get(arg->dev). During an interface shutdown (addrconf_ifdown), the dev->ip6_ptr can be cleared while a Router Advertisement (RA)-driven MTU update walk is still in progress. Because nexthop-backed routes can survive the initial flush, the walk may attempt to dereference a NULL idev pointer, resulting in a general protection fault. The fix introduces a NULL check to safely return 0 if the device pointer has been cleared.

Affected products

  • Linux Linux Kernel c0b220cf7d80 to 46c3b8191aad (mainline)

Timeline

  • 2026-06-18: disclosed: Initial patch authored
  • 2026-06-22: patched: Patch merged into mainline kernel
  • 2026-07-27: advisory: CVE published to NVD

References

Related threats