{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80646","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.779Z","datePublished":"2026-08-28T06:48:56.277Z","dateUpdated":"2026-08-29T06:21:41.550Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-29T06:21:41.550Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: guard against possible NULL deref in __in6_dev_stats_get()\n\ndev_get_by_index_rcu() could return NULL if the original physical\ndevice is unregistered.\n\nFound by Sashiko."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - Remote attackers reach ipv6_frag_rcv() through the standard IPv6 receive and local-delivery path (ipv6_rcv to ip6_protocol_deliver_rcu) by sending fragmented IPv6 packets to an Internet-facing host running IPv6 reassembly on a VRF/L3-master ingress path.\nAC:L - An attacker can repeatedly deliver IPv6 fragments and time them against concurrent netdev unregister (link teardown, container veth removal, or ip link del with CAP_NET_ADMIN in a user namespace), controlling both sides of the race rather than depending on uncontrollable layout.\nPR:N - Sending unauthenticated IPv6 fragments requires no kernel credentials; VRF/L3-master configuration is a deployment condition on routers and cloud hosts, not a privilege the attacker must hold to deliver the triggering traffic.\nUI:N - Exploitation needs only network delivery of fragmented IPv6 packets during interface teardown; no victim action such as opening files, clicking links, or mounting filesystems is required.\nS:U - The NULL dereference crashes the kernel on the receiving host but does not cross a VM, container, or IOMMU security boundary; impact stays within the same kernel security authority.\nC:N - The failure is a NULL pointer read in __in6_dev_get(NULL) after dev_get_by_index_rcu() returns NULL; there is no use-after-free, out-of-bounds read, or other information-disclosure primitive.\nI:N - The bug dereferences a NULL net_device pointer for statistics lookup only; it provides no memory write, corruption, or control-flow hijack primitive beyond crashing the kernel.\nA:H - The NULL dereference during IPv6 fragment receive/reassembly processing in softirq context causes a kernel OOPS or panic, fully denying availability on the affected system until reboot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/addrconf.h"],"versions":[{"version":"e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f","lessThan":"a23f2c68c6635e41404f189f8f7ae910738cebdb","status":"affected","versionType":"git"},{"version":"e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f","lessThan":"e14db43677946bf2095febd294bb3c13ab375ab7","status":"affected","versionType":"git"},{"version":"e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f","lessThan":"1a4adfbeb47a212a64539137411f1ca168474d33","status":"affected","versionType":"git"},{"version":"e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f","lessThan":"1e3db30a88815bae6e9d5db6f64ac735e615a07e","status":"affected","versionType":"git"},{"version":"e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f","lessThan":"952426a83ca75cea25c09d58944abafaa3ebd242","status":"affected","versionType":"git"},{"version":"e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f","lessThan":"0db1949084e85a72d174a7dea3259b94fe5a9305","status":"affected","versionType":"git"},{"version":"e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f","lessThan":"fc920c0659cdea5afd8721c1155a51564859e075","status":"affected","versionType":"git"},{"version":"e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f","lessThan":"507541c2a8eeb76c02bd2511958f73a8cfa3e1bc","status":"affected","versionType":"git"},{"version":"a24963500a4ec921ce9c2597e0a584e44513afae","status":"affected","versionType":"git"},{"version":"4.19.291","lessThan":"4.20","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/addrconf.h"],"versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.291"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a23f2c68c6635e41404f189f8f7ae910738cebdb"},{"url":"https://git.kernel.org/stable/c/e14db43677946bf2095febd294bb3c13ab375ab7"},{"url":"https://git.kernel.org/stable/c/1a4adfbeb47a212a64539137411f1ca168474d33"},{"url":"https://git.kernel.org/stable/c/1e3db30a88815bae6e9d5db6f64ac735e615a07e"},{"url":"https://git.kernel.org/stable/c/952426a83ca75cea25c09d58944abafaa3ebd242"},{"url":"https://git.kernel.org/stable/c/0db1949084e85a72d174a7dea3259b94fe5a9305"},{"url":"https://git.kernel.org/stable/c/fc920c0659cdea5afd8721c1155a51564859e075"},{"url":"https://git.kernel.org/stable/c/507541c2a8eeb76c02bd2511958f73a8cfa3e1bc"}],"title":"ipv6: guard against possible NULL deref in __in6_dev_stats_get()","x_generator":{"engine":"bippy-1.2.0"}}}}