Executive brief
The Linux kernel's IPv6 routing protocol for low-power networks (RPL) handler can crash when processing specially-crafted network packets if the network interface's MTU is changed at the same time. This denial-of-service vulnerability allows an attacker on a reachable network to cause the system to crash by flooding the interface with IPv6 ping packets while manipulating the MTU configuration, disrupting network availability.
Technical details
A NULL pointer dereference exists in ipv6_rpl_srh_rcv() where it dereferences idev from __in6_dev_get() without NULL checking when reading idev->cnf.rpl_seg_enabled. The root cause is a race condition: when an interface's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears dev->ip6_ptr via RCU_INIT_POINTER(); a packet that passed the idev check in ip6_rcv_core() can reach ipv6_rpl_srh_rcv() with dev->ip6_ptr already NULL. The vulnerability is triggered by network-reachable attackers flooding the receive interface with ping6 traffic while flapping the interface MTU between 1500 and 1200. The fix adds an idev NULL check in ipv6_rthdr_rcv() before calling ipv6_rpl_srh_rcv() or ipv6_srh_rcv(), ensuring packets are dropped safely with SKB_DROP_REASON_IPV6DISABLED. No user interaction or prior authentication is required.
Affected products
- Linux Linux kernel 7.2.0-rc7 and earlier versions with IPv6 RPL support
Timeline
- 2026-09-11: disclosed