Impact
A NULL pointer dereference in the IPv6 RPL segment routing header handling path can cause the Linux kernel to crash when the interface MTU falls below the minimum IPv6 threshold. The missing null check allows an attacker to trigger a kernel panic, effectively denying service to all users on the affected system. The vulnerability is a classic NULL dereference fault (CWE‑476).
Affected Systems
All Linux kernel implementations prior to the commit that adds the NULL‑check in ipv6_rthdr_rcv() are affected. Versions without the fix will crash when an SRH packet is processed on an interface whose MTU is temporarily lowered below IPV6_MIN_MTU.
Risk and Exploitability
Based on the description, it is inferred that the attack vector requires sending IPv6 packets containing a segment routing header to the target interface while the interface MTU is manipulated. The EPSS score of < 1% indicates a low probability of exploitation, yet the CVSS score of 7.5 reflects high severity. The vulnerability is not listed in the CISA KEV catalog, and no public exploit is known.
OpenCVE Enrichment
Debian DSA