Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: ip6t_rpfilter: reject routes without inet6_dev

ip6_route_lookup() can return an error-free route whose rt6i_idev is
NULL. Lowering an external nexthop device's MTU below IPV6_MIN_MTU tears
down its inet6_dev while fib6_ifdown() leaves routes using nexthop objects
in the FIB. An unprivileged user can construct this state with rtnetlink
in a private user and network namespace, then trigger a NULL dereference
through an IPv6 rpfilter lookup:

Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: rpfilter_mt (net/ipv6/netfilter/ip6t_rpfilter.c:75)
Call Trace:
ip6t_do_table (net/ipv6/netfilter/ip6_tables.c:316)
nf_hook_slow (net/netfilter/core.c:619)
ipv6_rcv (net/ipv6/ip6_input.c:351)
__netif_receive_skb_one_core (net/core/dev.c:6216)
process_backlog (net/core/dev.c:6680)
__napi_poll (net/core/dev.c:7739)
net_rx_action (net/core/dev.c:7959)
handle_softirqs (kernel/softirq.c:622)
do_softirq.part.0 (kernel/softirq.c:523)
__local_bh_enable_ip (kernel/softirq.c:450)
__dev_queue_xmit (net/core/dev.c:4913)
packet_sendmsg (net/packet/af_packet.c:3139)
__sys_sendto (net/socket.c:2252)
__x64_sys_sendto (net/socket.c:2259)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Kernel panic - not syncing: Fatal exception in interrupt

Reject routes without an inet6_dev immediately after lookup. Such routes
are not eligible for reverse-path filtering, and the check protects all
later rt6i_idev dereferences.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Kernel Panic / Denial of Service
Action: Apply Patch
AI Analysis

Impact

An unprivileged user can trigger a NULL pointer dereference in the Linux kernel’s IPv6 netfilter rpfilter module by creating a route that has no inet6_dev. When the kernel attempts to perform a rpfilter lookup on such a route, the null dereference causes a kernel panic, abruptly terminating the operating system and denying all services. This vulnerability is a classic memory safety flaw that leads to a direct system crash.

Affected Systems

The affected product is the Linux kernel, maintained by the Linux community. The vulnerability exists in all versions of the kernel prior to the fix, with no specific version range documented. The primary impacted component is the IPv6 netfilter rpfilter module that processes inbound IPv6 traffic in the kernel.

Risk and Exploitability

The CVSS score is not publicly disclosed, but the bug can be exploited by any unprivileged user who can manipulate routes in a private network namespace. By using the rtnetlink interface, a malicious actor can create a route with a missing inet6_dev, causing a NULL dereference during rpfilter lookups. An exploited kernel panic will bring down the entire system, leading to a denial of service. The EPSS score is unavailable; however, the known impact and lack of mitigations indicate a high risk. The vulnerability is not listed in CISA KEV, so widespread exploitation reports are not yet documented.

Generated by OpenCVE AI on October 9, 2026 at 09:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the ip6t_rpfilter null‑dereference fix.
  • If a patch cannot be applied immediately, temporarily disable the rp_filter netfilter module or configure the system to reject routes without inet6_dev until the kernel is updated.
  • Use ip -6 route show in each private network namespace to identify and remove any routes that lack an inet6_dev, preventing the kernel from later dereferencing a null pointer.

Generated by OpenCVE AI on October 9, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rpfilter: reject routes without inet6_dev ip6_route_lookup() can return an error-free route whose rt6i_idev is NULL. Lowering an external nexthop device's MTU below IPV6_MIN_MTU tears down its inet6_dev while fib6_ifdown() leaves routes using nexthop objects in the FIB. An unprivileged user can construct this state with rtnetlink in a private user and network namespace, then trigger a NULL dereference through an IPv6 rpfilter lookup: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: rpfilter_mt (net/ipv6/netfilter/ip6t_rpfilter.c:75) Call Trace: ip6t_do_table (net/ipv6/netfilter/ip6_tables.c:316) nf_hook_slow (net/netfilter/core.c:619) ipv6_rcv (net/ipv6/ip6_input.c:351) __netif_receive_skb_one_core (net/core/dev.c:6216) process_backlog (net/core/dev.c:6680) __napi_poll (net/core/dev.c:7739) net_rx_action (net/core/dev.c:7959) handle_softirqs (kernel/softirq.c:622) do_softirq.part.0 (kernel/softirq.c:523) __local_bh_enable_ip (kernel/softirq.c:450) __dev_queue_xmit (net/core/dev.c:4913) packet_sendmsg (net/packet/af_packet.c:3139) __sys_sendto (net/socket.c:2252) __x64_sys_sendto (net/socket.c:2259) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Kernel panic - not syncing: Fatal exception in interrupt Reject routes without an inet6_dev immediately after lookup. Such routes are not eligible for reverse-path filtering, and the check protects all later rt6i_idev dereferences.
Title netfilter: ip6t_rpfilter: reject routes without inet6_dev
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:19.425Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98379

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:56.250

Modified: 2026-10-09T08:16:56.250

Link: CVE-2026-98379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T10:00:05Z

Weaknesses