CVE-2026-98379: netfilter: ip6t_rpfilter: reject routes without inet6_dev
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ip6trpfilter: reject routes without inet6dev
ip6routelookup() can return an error-free route whose rt6iidev is NULL. Lowering an external nexthop device's MTU below IPV6MINMTU tears down its inet6dev while fib6ifdown() leaves routes using nexthop objects in the FIB. An unprivileged user can construct this state with rtnetlink in a private user and network namespace, then trigger a NULL dereference through an IPv6 rpfilter lookup:
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: rpfiltermt (net/ipv6/netfilter/ip6trpfilter.c:75) Call Trace: ip6tdotable (net/ipv6/netfilter/ip6tables.c:316) nfhookslow (net/netfilter/core.c:619) ipv6rcv (net/ipv6/ip6input.c:351) netifreceiveskbonecore (net/core/dev.c:6216) processbacklog (net/core/dev.c:6680) napipoll (net/core/dev.c:7739) netrxaction (net/core/dev.c:7959) handlesoftirqs (kernel/softirq.c:622) dosoftirq.part.0 (kernel/softirq.c:523) localbhenableip (kernel/softirq.c:450) devqueuexmit (net/core/dev.c:4913) packetsendmsg (net/packet/afpacket.c:3139) syssendto (net/socket.c:2252) x64syssendto (net/socket.c:2259) dosyscall64 (arch/x86/entry/syscall64.c:94) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:121) Kernel panic - not syncing: Fatal exception in interrupt
Reject routes without an inet6dev immediately after lookup. Such routes are not eligible for reverse-path filtering, and the check protects all later rt6iidev dereferences.
Affected Software
Event History
Frequently Asked Questions
Who can trigger this issue?
An unprivileged user can construct the triggering network state using rtnetlink within a private user and network namespace, then trigger the fault through an IPv6 rpfilter lookup.
What configuration and network state are required?
The issue requires IPv6 rpfilter processing and a route returned by ip6_route_lookup() with no associated inet6_dev. This can occur after an external nexthop device's MTU is lowered below IPV6_MIN_MTU, which tears down its inet6_dev while routes using nexthop objects remain in the FIB.
What is the impact when the issue is triggered?
The IPv6 rpfilter lookup can dereference a NULL rt6i_idev pointer in rpfilter_mt, producing a kernel general protection fault/null-pointer dereference.