CVE-2026-72392

Source
https://cve.org/CVERecord?id=CVE-2026-72392
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72392.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72392
Downstream
Published
2026-08-15T05:56:20.463Z
Modified
2026-08-16T03:48:41.013286065Z
Summary
ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fib6: fix NULL deref in fib6walkcontinue() on multi-batch dump

inet6dumpfib() saves its progress in cb->args[1] as a positional index within the current hash chain. Between batches, a concurrent fib6newtable() can insert a new table at the chain head, shifting all existing entries. The saved index then lands on a different table, causing fib6dumptable() to set w->root to the wrong table while w->node still points into the previous one. fib6walkcontinue() dereferences w->node->parent (NULL) and panics:

BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:fib6walkcontinue+0x6e/0x170 Call Trace: <TASK> fib6dumptable.isra.0+0xc5/0x240 inet6dumpfib+0xf6/0x420 rtnldumpit+0x30/0xa0 netlinkdump+0x15b/0x460 netlink_recvmsg+0x1d6/0x2a0 ___sysrecvmsg+0x17a/0x190

Fix by storing tb->tb6_id in cb->args[1] instead of a positional index. On resume, skip entries until the id matches; a concurrent head-insert can never match the saved id, so the walker always resumes on the correct table.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72392.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1b43af5480c351dbcb2eef478bafe179cbeb6e83
Fixed
89f9c5fee3c64c5cabc34e65599308fd3c879cf9
Fixed
27210d433a8c5fe6bf7278a04bbaeb49a81d0290
Fixed
059efb48dd746518898faaa9b965511009b59639
Fixed
d8a01d27873e04bebd357dc87859aa756e0b28b2
Fixed
110ccbd28c9444866fcc84ba96a2ad64fa6e95ae
Fixed
9facb861dc6b9b9ea9793ef5032a9a826f7a4229

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72392.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.19
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72392.json"