PT-2026-108765 · Linux · Linux
CVE-2026-98379
·
Published
2026-10-09
·
Updated
2026-10-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ip6t rpfilter: reject routes without inet6 dev
ip6 route lookup() can return an error-free route whose rt6i idev is
NULL. Lowering an external nexthop device's MTU below IPV6 MIN MTU tears
down its inet6 dev while fib6 ifdown() leaves routes using nexthop objects
in the FIB. An unprivileged user can construct this state with rtnetlink
in a private user and network namespace, then trigger a NULL dereference
through an IPv6 rpfilter lookup:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: rpfilter mt (net/ipv6/netfilter/ip6t rpfilter.c:75)
Call Trace:
ip6t do table (net/ipv6/netfilter/ip6 tables.c:316)
nf hook slow (net/netfilter/core.c:619)
ipv6 rcv (net/ipv6/ip6 input.c:351)
netif receive skb one core (net/core/dev.c:6216)
process backlog (net/core/dev.c:6680)
napi poll (net/core/dev.c:7739)
net rx action (net/core/dev.c:7959)
handle softirqs (kernel/softirq.c:622)
do softirq.part.0 (kernel/softirq.c:523)
local bh enable ip (kernel/softirq.c:450)
dev queue xmit (net/core/dev.c:4913)
packet sendmsg (net/packet/af packet.c:3139)
sys sendto (net/socket.c:2252)
x64 sys sendto (net/socket.c:2259)
do syscall 64 (arch/x86/entry/syscall 64.c:94)
entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt
Reject routes without an inet6 dev immediately after lookup. Such routes
are not eligible for reverse-path filtering, and the check protects all
later rt6i idev dereferences.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux