{"id":"CVE-2026-89561","summary":"ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()\n\nipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL\ncheck when reading idev-\u003ecnf.rpl_seg_enabled.\n\nWhen the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears\ndev-\u003eip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev\ncheck in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with\ndev-\u003eip6_ptr already NULL.\n\nReproduced by flooding the receiving interface with ping6 traffic while\nflapping its MTU between 1500 and 1200:\n\n BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070\n Read of size 4 at addr 00000000000006b4 by task ping6/394\n\n CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)\n Call Trace:\n  \u003cIRQ\u003e\n  kasan_report+0xc6/0x100\n  ipv6_rpl_srh_rcv+0xb3/0x1070\n  ip6_protocol_deliver_rcu+0x759/0x9a0\n  ip6_input_finish+0xa8/0x1b0\n  ip6_input+0xe1/0x490\n  ipv6_rcv+0x33d/0x460\n  __netif_receive_skb_one_core+0xd6/0x130\n  process_backlog+0x2cc/0xa00\n  __napi_poll.constprop.0+0x56/0x270\n  net_rx_action+0x327/0x730\n  handle_softirqs+0x11e/0x630\n  do_softirq+0xb3/0xf0\n  \u003c/IRQ\u003e\n\nBoth ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from\nipv6_rthdr_rcv(), which already has an idev lookup.\n\nFix the NULL dereference on the RPL path by checking idev in\nipv6_rthdr_rcv(), before it calls either function. The callees take idev as\nan argument and no longer call __in6_dev_get(), so the packet is now\ndropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.","modified":"2026-09-13T03:47:19.401923423Z","published":"2026-09-11T19:44:32.822Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89561.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/63f50e9f90d0287ad66a0955ebfc2d3a9c044a1c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/eab3a917cdcb182542a3aac6a0d2d30659ca9821"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f826df95332c07380206dbd54178b6eefb311aba"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89561.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89561"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3"},{"fixed":"63f50e9f90d0287ad66a0955ebfc2d3a9c044a1c"},{"fixed":"eab3a917cdcb182542a3aac6a0d2d30659ca9821"},{"fixed":"f826df95332c07380206dbd54178b6eefb311aba"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89561.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.7.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89561.json"}}],"schema_version":"1.9.0"}