CVE-2026-64116: ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()

Published Jul 19, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ipv6: ioam: add NULL check for idev in ipv6hopioam()

Reported by Sashiko:

The function ipv6hopioam() accesses in6devget(skb->dev)->cnf.ioam6enabled without validating the returned idev pointer. Because addrconfifdown() can concurrently clear dev->ip6ptr via RCU, in6devget() can return NULL during interface teardown, which could cause a NULL pointer dereference when processing an IOAM Hop-by-Hop option.

Let's add a check and use SKBDROPREASONIPV6DISABLED accordingly.

Affected Software

11 affected components
Linux Linux kernel
Linux Linux kernel>=5.15<5.15.210
Linux Linux kernel>=5.16<6.1.176
Linux Linux kernel>=6.2<6.6.143
Linux Linux kernel>=6.7<6.12.92
Linux Linux kernel>=6.13<6.18.34
Linux Linux kernel>=6.19<7.0.11
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4

Event History

Jul 19, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverity
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-64116?

CVE-2026-64116 has a high severity rating of 7.5.

2

What type of vulnerability is CVE-2026-64116?

CVE-2026-64116 is classified as a null pointer dereference vulnerability.

3

How does CVE-2026-64116 affect the Linux kernel?

CVE-2026-64116 allows access to the idev pointer in the ipv6_hop_ioam() function without proper validation, potentially leading to exploits.

4

How do I fix CVE-2026-64116?

To fix CVE-2026-64116, ensure that your Linux kernel is updated to the latest version where the NULL check for idev has been added.

5

Who reported CVE-2026-64116?

CVE-2026-64116 was reported by a user named Sashiko.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203