CVE-2026-89561
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()<br />
<br />
ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL<br />
check when reading idev->cnf.rpl_seg_enabled.<br />
<br />
When the device&#39;s MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears<br />
dev->ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev<br />
check in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with<br />
dev->ip6_ptr already NULL.<br />
<br />
Reproduced by flooding the receiving interface with ping6 traffic while<br />
flapping its MTU between 1500 and 1200:<br />
<br />
BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070<br />
Read of size 4 at addr 00000000000006b4 by task ping6/394<br />
<br />
CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)<br />
Call Trace:<br />
<br />
kasan_report+0xc6/0x100<br />
ipv6_rpl_srh_rcv+0xb3/0x1070<br />
ip6_protocol_deliver_rcu+0x759/0x9a0<br />
ip6_input_finish+0xa8/0x1b0<br />
ip6_input+0xe1/0x490<br />
ipv6_rcv+0x33d/0x460<br />
__netif_receive_skb_one_core+0xd6/0x130<br />
process_backlog+0x2cc/0xa00<br />
__napi_poll.constprop.0+0x56/0x270<br />
net_rx_action+0x327/0x730<br />
handle_softirqs+0x11e/0x630<br />
do_softirq+0xb3/0xf0<br />
<br />
<br />
Both ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from<br />
ipv6_rthdr_rcv(), which already has an idev lookup.<br />
<br />
Fix the NULL dereference on the RPL path by checking idev in<br />
ipv6_rthdr_rcv(), before it calls either function. The callees take idev as<br />
an argument and no longer call __in6_dev_get(), so the packet is now<br />
dropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA


