-

CVE-2026-64542

ipv6: ndisc: fix NULL deref in accept_untracked_na()

In the Linux kernel, the following vulnerability has been resolved:

ipv6: ndisc: fix NULL deref in accept_untracked_na()

accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev)
and dereferences idev->cnf.accept_untracked_na without a NULL check,
even though its only caller ndisc_recv_na() already fetched and
NULL-checked idev for the same device.

Both reads of dev->ip6_ptr run in the same RCU read-side critical
section, but a concurrent addrconf_ifdown() can clear dev->ip6_ptr
between them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown()
without the synchronize_net() that orders the unregister path, so the
re-fetch returns NULL and oopses:

 BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974)
 Read of size 4 at addr 0000000000000364
 Call Trace:
  <IRQ>
  ndisc_recv_na (net/ipv6/ndisc.c:974)
  icmpv6_rcv (net/ipv6/icmp.c:1193)
  ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479)
  ip6_input_finish (net/ipv6/ip6_input.c:534)
  ip6_input (net/ipv6/ip6_input.c:545)
  ip6_mc_input (net/ipv6/ip6_input.c:635)
  ipv6_rcv (net/ipv6/ip6_input.c:351)
  </IRQ>

It is reachable by an unprivileged user via a network namespace.

Pass the caller's already validated idev instead of re-fetching it; the
idev stays alive for the whole RCU critical section, so it is safe even
after dev->ip6_ptr has been cleared.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version aaa5f515b16b6b3e137779ffb4c9558bb58c1e75
Version < e5ba3017e46f275ad347e762e8eecacec5efa41d
Status affected
Version aaa5f515b16b6b3e137779ffb4c9558bb58c1e75
Version < 160d3f0d7a556ceae505dcab521a37057b4ce28f
Status affected
Version aaa5f515b16b6b3e137779ffb4c9558bb58c1e75
Version < 62c719203cb521b64fab74da94a81bdde5c18808
Status affected
Version aaa5f515b16b6b3e137779ffb4c9558bb58c1e75
Version < a6450f7cfae57b382cbaf66a577765c9a88b3c58
Status affected
Version aaa5f515b16b6b3e137779ffb4c9558bb58c1e75
Version < 63d1c23764de2309cedbb779c75188d257a09d9b
Status affected
Version aaa5f515b16b6b3e137779ffb4c9558bb58c1e75
Version < d186e942365acece7c56d39da05dd63bf95b280a
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.07
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/62c719203cb521b64fab74da94a81bdde5c18808
https://git.kernel.org/stable/c/a6450f7cfae57b382cbaf66a577765c9a88b3c58
https://git.kernel.org/stable/c/63d1c23764de2309cedbb779c75188d257a09d9b
https://git.kernel.org/stable/c/d186e942365acece7c56d39da05dd63bf95b280a
https://git.kernel.org/stable/c/160d3f0d7a556ceae505dcab521a37057b4ce28f
https://git.kernel.org/stable/c/e5ba3017e46f275ad347e762e8eecacec5efa41d