PT-2026-98638 · Linux · Linux

CVE-2026-97974

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: null-check fib6 node before accessing in ip6 del rt siblings()
syzbot reported a null-ptr-deref in ip6 del rt siblings() [0].
The stack trace hinted towards a null dereference of rt->fib6 node when fn->leaf is accessed in ip6 del rt siblings(). With RTNL FLAG DOIT UNLOCKED set, inet6 rtm delroute() operations run concurrently without acquiring the RTNL lock. In ip6 route del(), the route lookup happens under rcu read lock() without acquiring table->tb6 lock.
Between ip6 route del() looking up the route and ip6 del rt siblings() acquiring table->tb6 lock, another thread can modify the routing table. For example, when an ECMP route is replaced via RTM NEWROUTE with NLM F REPLACE, fib6 add rt2node() unlinks all old siblings and sets iter->fib6 node = NULL. A reproducer was found that triggers this [1].
Add a check to ensure rt->fib6 node is non-null before accessing it.
[0] KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027] RIP: 0010: ip6 del rt siblings+0x31e/0x7c0 net/ipv6/route.c:4056 Call Trace: ip6 route del+0x1054/0x1110 net/ipv6/route.c:4232 inet6 rtm delroute+0x5d7/0x6d0 net/ipv6/route.c:5669 rtnetlink rcv msg+0x802/0xc00 net/core/rtnetlink.c:7132 netlink rcv skb+0x226/0x4a0 net/netlink/af netlink.c:2556 netlink unicast kernel net/netlink/af netlink.c:1319 [inline] netlink unicast+0x7f5/0x990 net/netlink/af netlink.c:1345 netlink sendmsg+0x813/0xb40 net/netlink/af netlink.c:1900 sock sendmsg nosec+0x13a/0x180 net/socket.c:800 sock sendmsg net/socket.c:815 [inline] sys sendmsg+0x565/0x870 net/socket.c:2713 sys sendmsg+0x2a5/0x360 net/socket.c:2767 sys sendmsg net/socket.c:2799 [inline] do sys sendmsg net/socket.c:2804 [inline] se sys sendmsg net/socket.c:2802 [inline] x64 sys sendmsg+0x1b7/0x290 net/socket.c:2802 do syscall x64 arch/x86/entry/syscall 64.c:61 [inline] do syscall 64+0x166/0x520 arch/x86/entry/syscall 64.c:84 entry SYSCALL 64 after hwframe+0x77/0x7f
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97974

Produtos afetados

Linux