Impact
A null‑pointer dereference in the IPv6 neighbor discovery code can cause the Linux kernel to crash when the function accept_untracked_na() re‑fetches the inet6_dev structure and dereferences it without a NULL check. An attacker can trigger this fault from within a network namespace by sending crafted IPv6 packets that exercise the vulnerable code path. The resulting kernel oops leaves the affected host unstable and effectively denies service to all users on that system.
Affected Systems
Linux kernel instances that include the vulnerable code before the inclusion of commit 62c719203cb521b64fab74da94a81bdde5c18808 are impacted. Distributions shipping kernels older than this commit must consider themselves affected. The problem is specific to IPv6 neighbor discovery handling and requires that the device be present during packet reception in a network namespace.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, while the EPSS score of < 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV, so no known exploitation campaigns are reported. Attackers must have local access sufficient to inject crafted IPv6 traffic into the problematic kernel, such as via a network namespace or a raw IPv6 socket. The fault occurs during normal packet processing, so no advanced privileges or additional exploits are needed beyond the ability to send the packets.
OpenCVE Enrichment
Debian DLA
Debian DSA