CVE-2026-98379: netfilter: ip6t_rpfilter: reject routes without inet6_dev

Published Oct 9, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ip6trpfilter: reject routes without inet6dev

ip6routelookup() can return an error-free route whose rt6iidev is NULL. Lowering an external nexthop device's MTU below IPV6MINMTU tears down its inet6dev while fib6ifdown() leaves routes using nexthop objects in the FIB. An unprivileged user can construct this state with rtnetlink in a private user and network namespace, then trigger a NULL dereference through an IPv6 rpfilter lookup:

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: rpfiltermt (net/ipv6/netfilter/ip6trpfilter.c:75) Call Trace: ip6tdotable (net/ipv6/netfilter/ip6tables.c:316) nfhookslow (net/netfilter/core.c:619) ipv6rcv (net/ipv6/ip6input.c:351) netifreceiveskbonecore (net/core/dev.c:6216) processbacklog (net/core/dev.c:6680) napipoll (net/core/dev.c:7739) netrxaction (net/core/dev.c:7959) handlesoftirqs (kernel/softirq.c:622) dosoftirq.part.0 (kernel/softirq.c:523) localbhenableip (kernel/softirq.c:450) devqueuexmit (net/core/dev.c:4913) packetsendmsg (net/packet/afpacket.c:3139) syssendto (net/socket.c:2252) x64syssendto (net/socket.c:2259) dosyscall64 (arch/x86/entry/syscall64.c:94) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:121) Kernel panic - not syncing: Fatal exception in interrupt

Reject routes without an inet6dev immediately after lookup. Such routes are not eligible for reverse-path filtering, and the check protects all later rt6iidev dereferences.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 9, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
Description
Data Sourced
via NVD·08:16 AM
Description

Frequently Asked Questions

1

Who can trigger this issue?

An unprivileged user can construct the triggering network state using rtnetlink within a private user and network namespace, then trigger the fault through an IPv6 rpfilter lookup.

2

What configuration and network state are required?

The issue requires IPv6 rpfilter processing and a route returned by ip6_route_lookup() with no associated inet6_dev. This can occur after an external nexthop device's MTU is lowered below IPV6_MIN_MTU, which tears down its inet6_dev while routes using nexthop objects remain in the FIB.

3

What is the impact when the issue is triggered?

The IPv6 rpfilter lookup can dereference a NULL rt6i_idev pointer in rpfilter_mt, producing a kernel general protection fault/null-pointer dereference.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203