Executive brief
The Linux kernel's IPv6 routing table code can crash when enumerating routing tables while concurrent table creation is happening. A concurrent operation inserting a new routing table can cause the kernel to dereference a NULL pointer, resulting in a kernel panic that disrupts network services on affected systems.
Technical details
This is a NULL pointer dereference vulnerability in the IPv6 FIB (Forwarding Information Base) walker code. The inet6_dump_fib() function saves its progress as a positional index, but when fib6_new_table() concurrently inserts a new table at the hash chain head, the saved index can point to the wrong table. This causes fib6_walk_continue() to dereference w->node->parent on a stale node pointer, triggering a kernel NULL pointer dereference panic. The fix changes the saved state from a positional index to a table ID, ensuring the walker resumes on the correct table regardless of concurrent insertions. Attack vector is local and requires no special privileges—any process can trigger routing table enumeration via netlink sockets.
Affected products
- Linux Linux kernel Affected since v2.6.13+ (kernel 3.14+); patched in stable branches as of 2026-07-24
Timeline
- 2026-08-15: disclosed: Published on NVD
- 2026-06-25: patched: Upstream fix commit 9facb861dc6b9b9ea9793ef5032a9a826f7a4229 authored
- 2026-07-24: patched: Included in Linux stable releases