← All Advisories

CVE-2026-89561

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89561

Key Details

CVECVE-2026-89561
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()

ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL

check when reading idev->cnf.rpl_seg_enabled.

When the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears

dev->ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev

check in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with

dev->ip6_ptr already NULL.

Reproduced by flooding the receiving interface with ping6 traffic while

flapping its MTU between 1500 and 1200:

BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070

Read of size 4 at addr 00000000000006b4 by task ping6/394

CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)

Call Trace:

<IRQ>

kasan_report+0xc6/0x100

ipv6_rpl_srh_rcv+0xb3/0x1070

ip6_protocol_deliver_rcu+0x759/0x9a0

ip6_input_finish+0xa8/0x1b0

ip6_input+0xe1/0x490

ipv6_rcv+0x33d/0x460

__netif_receive_skb_one_core+0xd6/0x130

process_backlog+0x2cc/0xa00

__napi_poll.constprop.0+0x56/0x270

net_rx_action+0x327/0x730

handle_softirqs+0x11e/0x630

do_softirq+0xb3/0xf0

</IRQ>

Both ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from

ipv6_rthdr_rcv(), which already has an idev lookup.

Fix the NULL dereference on the RPL path by checking idev in

ipv6_rthdr_rcv(), before it calls either function. The callees take idev as

an argument and no longer call __in6_dev_get(), so the packet is now

dropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89561
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89561