CVE-2026-89561
Received Received - Intake

NULL Pointer Dereference in Linux Kernel IPv6 RPL

Vulnerability report for CVE-2026-89561, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-21

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL check when reading idev->cnf.rpl_seg_enabled. When the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears dev->ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev check in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with dev->ip6_ptr already NULL. Reproduced by flooding the receiving interface with ping6 traffic while flapping its MTU between 1500 and 1200: BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070 Read of size 4 at addr 00000000000006b4 by task ping6/394 CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full) Call Trace: <IRQ> kasan_report+0xc6/0x100 ipv6_rpl_srh_rcv+0xb3/0x1070 ip6_protocol_deliver_rcu+0x759/0x9a0 ip6_input_finish+0xa8/0x1b0 ip6_input+0xe1/0x490 ipv6_rcv+0x33d/0x460 __netif_receive_skb_one_core+0xd6/0x130 process_backlog+0x2cc/0xa00 __napi_poll.constprop.0+0x56/0x270 net_rx_action+0x327/0x730 handle_softirqs+0x11e/0x630 do_softirq+0xb3/0xf0 </IRQ> Both ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from ipv6_rthdr_rcv(), which already has an idev lookup. Fix the NULL dereference on the RPL path by checking idev in ipv6_rthdr_rcv(), before it calls either function. The callees take idev as an argument and no longer call __in6_dev_get(), so the packet is now dropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-21
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
linux_kernel linux_kernel *
linux linux_kernel 7.2.0-rc7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference in the Linux kernel's IPv6 RPL (Routing Protocol for Low-Power and Lossy Networks) handling. The issue occurs in the function ipv6_rpl_srh_rcv() which accesses a network interface device structure (idev) without checking if it is NULL. When the device's MTU drops below a threshold, the idev pointer is cleared, but packets may still reach this function, causing a kernel crash.

Detection Guidance

This vulnerability may trigger a kernel panic or NULL pointer dereference when IPv6 RPL (Routing Protocol for Low-Power and Lossy Networks) packets are processed on an interface with a low MTU. Monitor kernel logs for KASAN reports or NULL pointer dereference errors in ipv6_rpl_srh_rcv. Check for crashes or hangs during IPv6 traffic, especially when MTU changes occur.

Impact Analysis

This vulnerability can cause a kernel panic or system crash when processing IPv6 packets with RPL headers on affected systems. Attackers could exploit this by sending specially crafted packets to trigger the NULL pointer dereference, leading to denial-of-service conditions. Systems running vulnerable Linux kernel versions are at risk.

Compliance Impact

This vulnerability is a NULL pointer dereference in the Linux kernel's IPv6 RPL (Routing Protocol for Low-power and Lossy Networks) handling. It does not directly relate to data privacy, access control, or audit logging, which are the primary concerns for GDPR and HIPAA compliance. The issue could potentially cause system instability or denial of service, but there is no evidence it exposes or leaks sensitive data.

Mitigation Strategies

Apply the Linux kernel patch that fixes the NULL dereference in ipv6_rpl_srh_rcv(). Disable IPv6 RPL if not needed. Monitor network traffic for unusual IPv6 packets and ensure MTU settings are stable. Update to a kernel version containing the fix (7.2.0-rc7 or later).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89561. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart