Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64538

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
27/07/2026
Última modificación:
27/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().<br /> <br /> fib6_nh_mtu_change() re-fetches idev via __in6_dev_get(arg-&gt;dev) and<br /> dereferences idev-&gt;cnf.mtu6 without a NULL check. addrconf_ifdown()<br /> clears dev-&gt;ip6_ptr with RCU_INIT_POINTER() after rt6_disable_ip() has<br /> released tb6_lock, so the RA-driven MTU walk can observe a NULL idev and<br /> oops. The caller rt6_mtu_change_route() guards its own __in6_dev_get(),<br /> but this re-fetch is unguarded; nexthop-backed routes survive<br /> addrconf_ifdown()&amp;#39;s flush, so the walk still reaches it after ip6_ptr is<br /> nulled.<br /> <br /> Return 0 when idev is NULL, matching rt6_mtu_change_route() and the<br /> fib6_mtu() fix in commit 5ad509c1fdad ("ipv6: Fix null-ptr-deref in<br /> fib6_mtu().").<br /> <br /> Oops: general protection fault, ... KASAN: null-ptr-deref in range<br /> [0x00000000000002a8-0x00000000000002af]<br /> RIP: 0010:fib6_nh_mtu_change+0x203/0x990<br /> rt6_mtu_change_route+0x141/0x1d0<br /> __fib6_clean_all+0xd0/0x160<br /> rt6_mtu_change+0xb4/0x100<br /> ndisc_router_discovery+0x24b5/0x2cb0<br /> icmpv6_rcv+0x12e9/0x1710<br /> ipv6_rcv+0x39b/0x410

Impacto