CVE-2026-72429: ipv6: ioam: fix type confusion of dst_entry
In the Linux kernel, the following vulnerability has been resolved:
ipv6: ioam: fix type confusion of dstentry
IOAM uses a dummy dstentry(nulldst) to mark that the destination should not be changed after the transformation. This dst is stored in the IOAM lwt state and may be passed to dstcachesetip6().
However, the IPv6 dst cache path eventually calls rt6getcookie(), which treats the dstentry as part of a struct rt6info. Since the nulldst was embedded directly as a struct dstentry in struct ioam6lwt, this resulted in an invalid cast and rt6getcookie() reading fields from the wrong object.
In practice, the wrong cookie is not used while dst->obsolete is zero, but rt6getcookie() may also access per-cpu value when rt->sernum is zero. In this case, rt->sernum aliases ioam6lwt::cache::resetts, which can become zero, making this a potential invalid pointer access.
Fix this by embedding a full struct rt6info for the dummy IPv6 route and passing its dst member to the dst APIs.