NULL pointer dereference in Linux kernel - CVE-2026-98379
Published: October 9, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service by triggering a kernel panic.
The vulnerability exists due to a null pointer dereference in the Linux kernel IPv6 reverse-path filtering component when processing a route without an inet6_dev. A local user can use rtnetlink to lower an external nexthop device's MTU below IPV6_MIN_MTU and trigger an IPv6 reverse-path filtering lookup to cause a denial of service by triggering a kernel panic.
An unprivileged user can construct the required state within a private user namespace and network namespace.
Affected software
How to mitigate CVE-2026-98379
External References
- https://git.kernel.org/stable/c/1681ab6dd1271f2f36047490793b78b1848bbcc9
- https://git.kernel.org/stable/c/1b9b5323725e458906c7620a3bc10398b51ad954
- https://git.kernel.org/stable/c/290c96e5d9471d1ded9ab1e8ffbb04f6ee7b0f40
- https://git.kernel.org/stable/c/3a7384bc2e66217c9a01a392281334f4423740a0
- https://git.kernel.org/stable/c/65487e9e99431ffcf05024a817f51ee4e3bd9b47
- https://git.kernel.org/stable/c/eafe081ea77d25b5c8e601680671b4ecb4520e7d
- https://git.kernel.org/stable/c/f49da48bd679cfee646d6a40dd02b1933de577d1
- https://git.kernel.org/stable/c/f4de78756b0fddbd125b2b1b77c74f2eccc8e977