{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89561","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.725Z","datePublished":"2026-09-11T19:44:32.822Z","dateUpdated":"2026-09-21T13:14:27.162Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-21T13:14:27.162Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()\n\nipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL\ncheck when reading idev->cnf.rpl_seg_enabled.\n\nWhen the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears\ndev->ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev\ncheck in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with\ndev->ip6_ptr already NULL.\n\nReproduced by flooding the receiving interface with ping6 traffic while\nflapping its MTU between 1500 and 1200:\n\n BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070\n Read of size 4 at addr 00000000000006b4 by task ping6/394\n\n CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)\n Call Trace:\n  <IRQ>\n  kasan_report+0xc6/0x100\n  ipv6_rpl_srh_rcv+0xb3/0x1070\n  ip6_protocol_deliver_rcu+0x759/0x9a0\n  ip6_input_finish+0xa8/0x1b0\n  ip6_input+0xe1/0x490\n  ipv6_rcv+0x33d/0x460\n  __netif_receive_skb_one_core+0xd6/0x130\n  process_backlog+0x2cc/0xa00\n  __napi_poll.constprop.0+0x56/0x270\n  net_rx_action+0x327/0x730\n  handle_softirqs+0x11e/0x630\n  do_softirq+0xb3/0xf0\n  </IRQ>\n\nBoth ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from\nipv6_rthdr_rcv(), which already has an idev lookup.\n\nFix the NULL dereference on the RPL path by checking idev in\nipv6_rthdr_rcv(), before it calls either function. The callees take idev as\nan argument and no longer call __in6_dev_get(), so the packet is now\ndropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - ipv6_rpl_srh_rcv() runs on the IPv6 local-delivery path (ipv6_rcv → ip6_protocol_deliver_rcu → ipv6_rthdr_rcv) for any unicast packet with Routing Header type 3; a remote attacker can deliver such packets over the network with no local access.\nAC:L - The attacker drives both sides of the race by flooding type-3 routing-header packets while concurrently dropping the ingress MTU below IPV6_MIN_MTU or deleting the netdev, and the window is large because ip6_rcv_core() drops RCU before extension-header processing.\nPR:N - Sending an unauthenticated IPv6 packet with a type-3 routing header requires no credentials; the NULL deref occurs before the rpl_seg_enabled check, and ip6_ptr teardown also occurs during ordinary container/veth lifecycle on shared hosts.\nUI:N - Exploitation needs only delivery of IPv6 routing-header packets during concurrent interface MTU/teardown; no victim action such as opening a file, mounting a filesystem, or clicking a link is required.\nS:U - A successful trigger oopses the same host kernel that processes the packet and does not cross a VM, hypervisor, IOMMU, or other security-authority boundary.\nC:N - The fault is a pure NULL pointer read of idev->cnf.rpl_seg_enabled at a fixed offset, causing an immediate page fault with no use-after-free, out-of-bounds read, or other information-disclosure primitive.\nI:N - This is a read-side NULL dereference only; there is no memory write, type confusion, or control-flow hijack primitive beyond crashing the kernel.\nA:H - The NULL dereference occurs in softirq context during IPv6 receive and produces a kernel oops or panic, as shown by the KASAN report in ipv6_rpl_srh_rcv, fully denying availability on the affected system."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/exthdrs.c"],"versions":[{"version":"8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3","lessThan":"e7123e10c86eb88eaa90537dd1f232706de2d308","status":"affected","versionType":"git"},{"version":"8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3","lessThan":"63f50e9f90d0287ad66a0955ebfc2d3a9c044a1c","status":"affected","versionType":"git"},{"version":"8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3","lessThan":"eab3a917cdcb182542a3aac6a0d2d30659ca9821","status":"affected","versionType":"git"},{"version":"8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3","lessThan":"f826df95332c07380206dbd54178b6eefb311aba","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ipv6/exthdrs.c"],"versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e7123e10c86eb88eaa90537dd1f232706de2d308"},{"url":"https://git.kernel.org/stable/c/63f50e9f90d0287ad66a0955ebfc2d3a9c044a1c"},{"url":"https://git.kernel.org/stable/c/eab3a917cdcb182542a3aac6a0d2d30659ca9821"},{"url":"https://git.kernel.org/stable/c/f826df95332c07380206dbd54178b6eefb311aba"}],"title":"ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()","x_generator":{"engine":"bippy-1.2.0"}}}}