NULL pointer dereference in Linux kernel - CVE-2026-64538
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in fib6_nh_mtu_change() when processing router advertisement-driven MTU changes. A remote attacker can send a specially crafted ICMPv6 router advertisement to cause a denial of service.
The issue can occur during interface teardown when the IPv6 device pointer has been cleared while nexthop-backed routes are still being walked.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64538
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/1451deca9896957159f0666520a792c1b861af4f
- https://git.kernel.org/stable/c/302d57ed7872838b40e56a868fb4c7da7da606e9
- https://git.kernel.org/stable/c/46c3b8191aad3d032776bf3bebf03efdf5f4b905
- https://git.kernel.org/stable/c/6428634f7a0b7878144b4925c37856bef3224967
- https://git.kernel.org/stable/c/80600b5d0f3ecb9324120dc95b5e915130f516c5
- https://git.kernel.org/stable/c/b0d0eb13a0441a8ebf4f227843deaf494f1e2c33
- https://git.kernel.org/stable/c/b2c70dd3326809429b709a9c7e9220d29923051a
- https://git.kernel.org/stable/c/d08d019f2f43a6f9a71e81868bbc326b3afaf37b