PT-2026-98638 · Linux · Linux
CVE-2026-97974
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: null-check fib6 node before accessing in ip6 del rt siblings()
syzbot reported a null-ptr-deref in ip6 del rt siblings() [0].
The stack trace hinted towards a null dereference of rt->fib6 node when
fn->leaf is accessed in ip6 del rt siblings(). With
RTNL FLAG DOIT UNLOCKED set, inet6 rtm delroute() operations run
concurrently without acquiring the RTNL lock. In ip6 route del(), the
route lookup happens under rcu read lock() without acquiring
table->tb6 lock.
Between ip6 route del() looking up the route and ip6 del rt siblings()
acquiring table->tb6 lock, another thread can modify the routing table.
For example, when an ECMP route is replaced via RTM NEWROUTE with
NLM F REPLACE, fib6 add rt2node() unlinks all old siblings and sets
iter->fib6 node = NULL. A reproducer was found that triggers this [1].
Add a check to ensure rt->fib6 node is non-null before accessing it.
[0]
KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]
RIP: 0010: ip6 del rt siblings+0x31e/0x7c0 net/ipv6/route.c:4056
Call Trace:
ip6 route del+0x1054/0x1110 net/ipv6/route.c:4232
inet6 rtm delroute+0x5d7/0x6d0 net/ipv6/route.c:5669
rtnetlink rcv msg+0x802/0xc00 net/core/rtnetlink.c:7132
netlink rcv skb+0x226/0x4a0 net/netlink/af netlink.c:2556
netlink unicast kernel net/netlink/af netlink.c:1319 [inline]
netlink unicast+0x7f5/0x990 net/netlink/af netlink.c:1345
netlink sendmsg+0x813/0xb40 net/netlink/af netlink.c:1900
sock sendmsg nosec+0x13a/0x180 net/socket.c:800
sock sendmsg net/socket.c:815 [inline]
sys sendmsg+0x565/0x870 net/socket.c:2713
sys sendmsg+0x2a5/0x360 net/socket.c:2767
sys sendmsg net/socket.c:2799 [inline]
do sys sendmsg net/socket.c:2804 [inline]
se sys sendmsg net/socket.c:2802 [inline]
x64 sys sendmsg+0x1b7/0x290 net/socket.c:2802
do syscall x64 arch/x86/entry/syscall 64.c:61 [inline]
do syscall 64+0x166/0x520 arch/x86/entry/syscall 64.c:84
entry SYSCALL 64 after hwframe+0x77/0x7f
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux