CVE-2026-98379

Source
https://cve.org/CVERecord?id=CVE-2026-98379
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98379.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98379
Downstream
Published
2026-10-09T07:34:19Z
Modified
2026-10-10T02:47:32Z
Summary
netfilter: ip6t_rpfilter: reject routes without inet6_dev
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ip6t_rpfilter: reject routes without inet6_dev

ip6_route_lookup() can return an error-free route whose rt6i_idev is NULL. Lowering an external nexthop device's MTU below IPV6_MIN_MTU tears down its inet6_dev while fib6_ifdown() leaves routes using nexthop objects in the FIB. An unprivileged user can construct this state with rtnetlink in a private user and network namespace, then trigger a NULL dereference through an IPv6 rpfilter lookup:

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: rpfilter_mt (net/ipv6/netfilter/ip6t_rpfilter.c:75) Call Trace: ip6t_do_table (net/ipv6/netfilter/ip6_tables.c:316) nf_hook_slow (net/netfilter/core.c:619) ipv6_rcv (net/ipv6/ip6_input.c:351) __netif_receive_skb_one_core (net/core/dev.c:6216) process_backlog (net/core/dev.c:6680) __napi_poll (net/core/dev.c:7739) net_rx_action (net/core/dev.c:7959) handle_softirqs (kernel/softirq.c:622) do_softirq.part.0 (kernel/softirq.c:523) __local_bh_enable_ip (kernel/softirq.c:450) __dev_queue_xmit (net/core/dev.c:4913) packet_sendmsg (net/packet/af_packet.c:3139) __sys_sendto (net/socket.c:2252) __x64_sys_sendto (net/socket.c:2259) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Kernel panic - not syncing: Fatal exception in interrupt

Reject routes without an inet6_dev immediately after lookup. Such routes are not eligible for reverse-path filtering, and the check protects all later rt6i_idev dereferences.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98379.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e26f9a480fb6c1b614660e824d69a74e2ce990f3
Fixed
f4de78756b0fddbd125b2b1b77c74f2eccc8e977
Fixed
1681ab6dd1271f2f36047490793b78b1848bbcc9
Fixed
65487e9e99431ffcf05024a817f51ee4e3bd9b47
Fixed
f49da48bd679cfee646d6a40dd02b1933de577d1
Fixed
290c96e5d9471d1ded9ab1e8ffbb04f6ee7b0f40
Fixed
eafe081ea77d25b5c8e601680671b4ecb4520e7d
Fixed
3a7384bc2e66217c9a01a392281334f4423740a0
Fixed
1b9b5323725e458906c7620a3bc10398b51ad954

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98379.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.3.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.55
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98379.json"