PT-2026-108765 · Linux · Linux

CVE-2026-98379

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ip6t rpfilter: reject routes without inet6 dev
ip6 route lookup() can return an error-free route whose rt6i idev is NULL. Lowering an external nexthop device's MTU below IPV6 MIN MTU tears down its inet6 dev while fib6 ifdown() leaves routes using nexthop objects in the FIB. An unprivileged user can construct this state with rtnetlink in a private user and network namespace, then trigger a NULL dereference through an IPv6 rpfilter lookup:
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: rpfilter mt (net/ipv6/netfilter/ip6t rpfilter.c:75) Call Trace: ip6t do table (net/ipv6/netfilter/ip6 tables.c:316) nf hook slow (net/netfilter/core.c:619) ipv6 rcv (net/ipv6/ip6 input.c:351) netif receive skb one core (net/core/dev.c:6216) process backlog (net/core/dev.c:6680) napi poll (net/core/dev.c:7739) net rx action (net/core/dev.c:7959) handle softirqs (kernel/softirq.c:622) do softirq.part.0 (kernel/softirq.c:523) local bh enable ip (kernel/softirq.c:450) dev queue xmit (net/core/dev.c:4913) packet sendmsg (net/packet/af packet.c:3139) sys sendto (net/socket.c:2252) x64 sys sendto (net/socket.c:2259) do syscall 64 (arch/x86/entry/syscall 64.c:94) entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121) Kernel panic - not syncing: Fatal exception in interrupt
Reject routes without an inet6 dev immediately after lookup. Such routes are not eligible for reverse-path filtering, and the check protects all later rt6i idev dereferences.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98379

Affected Products

Linux