Impact
In the Linux kernel, an unchecked dereference in the function fib6_nh_mtu_change() can cause a kernel oops whenever the system performs an IPv6 MTU walk after an interface has been brought down. The dereference occurs after the address configuration subsystem clears the ipv6 pointer, allowing the routine to observe a NULL interface and crash. The resulting kernel panic stops all processing on the affected core, leading to a denial of service.
Affected Systems
The flaw is present in all publicly released Linux kernel versions prior to the commit that introduced the null-check. The affected product is the Linux kernel as distributed by most Linux distributions. No specific distribution or kernel version was enumerated in the advisory, so all users of older kernels that have not applied the patch are potentially affected.
Risk and Exploitability
The CVE has a CVSS score of 7.0 and an EPSS score of less than 1%. It is inferred that the attack vector could involve remote network traffic. It is not listed in the CISA KEV catalog. Because the fault originates during an IPv6 address‑configuration event that can be triggered by incoming network traffic (ICMPv6 router advertisements or neighbor solicitations), the vulnerability could be exploited remotely. An attacker who can cause the kernel to perform the MTU walk after a link‑down event would induce a kernel crash, causing the host to reboot or become unresponsive. As such, the risk is high for availability, and the vulnerability should be fixed immediately.
OpenCVE Enrichment
Debian DLA
Debian DSA