CVE-2024-56646: ipv6: avoid possible NULL deref in modify_prefix_route()

Published Dec 27, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ipv6: avoid possible NULL deref in modifyprefixroute()

syzbot found a NULL deref [1] in modifyprefixroute(), caused by one fib6info without a fib6table pointer set.

This can happen for net->ipv6.fib6nullentry

[1] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000006: 0000 [#1] PREEMPT SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037] CPU: 1 UID: 0 PID: 5837 Comm: syz-executor888 Not tainted 6.12.0-syzkaller-09567-g7eef7e306d3c #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 RIP: 0010:lockacquire+0xe4/0x3c40 kernel/locking/lockdep.c:5089 Code: 08 84 d2 0f 85 15 14 00 00 44 8b 0d ca 98 f5 0e 45 85 c9 0f 84 b4 0e 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 e2 48 c1 ea 03 <80> 3c 02 00 0f 85 96 2c 00 00 49 8b 04 24 48 3d a0 07 7f 93 0f 84 RSP: 0018:ffffc900035d7268 EFLAGS: 00010006 RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000006 RSI: 1ffff920006bae5f RDI: 0000000000000030 RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000001 R10: ffffffff90608e17 R11: 0000000000000001 R12: 0000000000000030 R13: ffff888036334880 R14: 0000000000000000 R15: 0000000000000000 FS: 0000555579e90380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007ffc59cc4278 CR3: 0000000072b54000 CR4: 00000000003526f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> lockacquire.part.0+0x11b/0x380 kernel/locking/lockdep.c:5849 rawspinlockbh include/linux/spinlockapismp.h:126 [inline] rawspinlockbh+0x33/0x40 kernel/locking/spinlock.c:178 spinlockbh include/linux/spinlock.h:356 [inline] modifyprefixroute+0x30b/0x8b0 net/ipv6/addrconf.c:4831 inet6addrmodify net/ipv6/addrconf.c:4923 [inline] inet6rtmnewaddr+0x12c7/0x1ab0 net/ipv6/addrconf.c:5055 rtnetlinkrcvmsg+0x3c7/0xea0 net/core/rtnetlink.c:6920 netlinkrcvskb+0x16b/0x440 net/netlink/afnetlink.c:2541 netlinkunicastkernel net/netlink/afnetlink.c:1321 [inline] netlinkunicast+0x53c/0x7f0 net/netlink/afnetlink.c:1347 netlinksendmsg+0x8b8/0xd70 net/netlink/afnetlink.c:1891 socksendmsgnosec net/socket.c:711 [inline] socksendmsg net/socket.c:726 [inline] syssendmsg+0xaaf/0xc90 net/socket.c:2583 syssendmsg+0x135/0x1e0 net/socket.c:2637 syssendmsg+0x16e/0x220 net/socket.c:2669 dosyscallx64 arch/x86/entry/common.c:52 [inline] dosyscall64+0xcd/0x250 arch/x86/entry/common.c:83 entrySYSCALL64afterhwframe+0x77/0x7f RIP: 0033:0x7fd1dcef8b79 Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffc59cc4378 EFLAGS: 00000246 ORIGRAX: 000000000000002e RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fd1dcef8b79 RDX: 0000000000040040 RSI: 0000000020000140 RDI: 0000000000000004 RBP: 00000000000113fd R08: 0000000000000006 R09: 0000000000000006 R10: 0000000000000006 R11: 0000000000000246 R12: 00007ffc59cc438c R13: 431bde82d7b634db R14: 0000000000000001 R15: 0000000000000001 </TASK>

Other sources

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

3 affected componentsFixes available
Linux Linux kernel>=6.9<6.12.5
Linux Linux kernel=6.13-rc1
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.27-1

Event History

Dec 27, 2024
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 27, 2025
Data Sourced
via Launchpad·06:46 PM
Description
Apr 4, 2025
Data Sourced
via Ubuntu·06:46 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-56646?

The severity of CVE-2024-56646 is categorized as high due to the potential for a NULL pointer dereference which could lead to a system crash.

2

How do I fix CVE-2024-56646?

To fix CVE-2024-56646, you should update your Linux kernel to version 6.13 or later.

3

What software is affected by CVE-2024-56646?

CVE-2024-56646 affects the Linux kernel versions between 6.9 and 6.12.5, as well as version 6.13-rc1.

4

What are the implications of CVE-2024-56646 on system security?

CVE-2024-56646 may allow an attacker to cause a denial of service (DoS) by triggering a NULL dereference in the IPv6 routing code.

5

When was CVE-2024-56646 discovered?

CVE-2024-56646 was discovered as part of an ongoing analysis and reporting process by the syzbot tool.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203