CVE-2026-89561

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()<br /> <br /> ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL<br /> check when reading idev-&gt;cnf.rpl_seg_enabled.<br /> <br /> When the device&amp;#39;s MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears<br /> dev-&gt;ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev<br /> check in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with<br /> dev-&gt;ip6_ptr already NULL.<br /> <br /> Reproduced by flooding the receiving interface with ping6 traffic while<br /> flapping its MTU between 1500 and 1200:<br /> <br /> BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070<br /> Read of size 4 at addr 00000000000006b4 by task ping6/394<br /> <br /> CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)<br /> Call Trace:<br /> <br /> kasan_report+0xc6/0x100<br /> ipv6_rpl_srh_rcv+0xb3/0x1070<br /> ip6_protocol_deliver_rcu+0x759/0x9a0<br /> ip6_input_finish+0xa8/0x1b0<br /> ip6_input+0xe1/0x490<br /> ipv6_rcv+0x33d/0x460<br /> __netif_receive_skb_one_core+0xd6/0x130<br /> process_backlog+0x2cc/0xa00<br /> __napi_poll.constprop.0+0x56/0x270<br /> net_rx_action+0x327/0x730<br /> handle_softirqs+0x11e/0x630<br /> do_softirq+0xb3/0xf0<br /> <br /> <br /> Both ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from<br /> ipv6_rthdr_rcv(), which already has an idev lookup.<br /> <br /> Fix the NULL dereference on the RPL path by checking idev in<br /> ipv6_rthdr_rcv(), before it calls either function. The callees take idev as<br /> an argument and no longer call __in6_dev_get(), so the packet is now<br /> dropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.