Impact
An unprivileged user can trigger a NULL pointer dereference in the Linux kernel’s IPv6 netfilter rpfilter module by creating a route that has no inet6_dev. When the kernel attempts to perform a rpfilter lookup on such a route, the null dereference causes a kernel panic, abruptly terminating the operating system and denying all services. This vulnerability is a classic memory safety flaw that leads to a direct system crash.
Affected Systems
The affected product is the Linux kernel, maintained by the Linux community. The vulnerability exists in all versions of the kernel prior to the fix, with no specific version range documented. The primary impacted component is the IPv6 netfilter rpfilter module that processes inbound IPv6 traffic in the kernel.
Risk and Exploitability
The CVSS score is not publicly disclosed, but the bug can be exploited by any unprivileged user who can manipulate routes in a private network namespace. By using the rtnetlink interface, a malicious actor can create a route with a missing inet6_dev, causing a NULL dereference during rpfilter lookups. An exploited kernel panic will bring down the entire system, leading to a denial of service. The EPSS score is unavailable; however, the known impact and lack of mitigations indicate a high risk. The vulnerability is not listed in CISA KEV, so widespread exploitation reports are not yet documented.
OpenCVE Enrichment