CVE-2026-23300

MEDIUM EPSS 2.4%
Published Mar 25, 20263mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Mar 25, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop When a standalone IPv6 nexthop object is created with a loopback device (e.g., "ip -6 nexthop add id 100 dev lo"), fib6_nh_init() misclassifies it as a reject route. This is because nexthop objects have no destination prefix (fc_dst=::), causing fib6_is_reject() to match any loopback nexthop. The reject path skips fib_nh_common_init(), leaving nhc_pcpu_rth_output unallocated. If an IPv4 route later references this nexthop, __mkroute_output() dereferences NULL nhc_pcpu_rth_output and panics. Simplify the check in fib6_nh_init() to only match explicit reject routes (RTF_REJECT) instead of using fib6_is_reject(). The loopback promotion heuristic in fib6_is_reject() is handled separately by ip6_route_info_create_nh(). After this change, the three cases behave as follows: 1. Explicit reject route ("ip -6 route add unreachable 2001:db8::/64"): RTF_REJECT is set, enters reject path, skips fib_nh_common_init(). No behavior change. 2. Implicit loopback reject route ("ip -6 route add 2001:db8::/32 dev lo"): RTF_REJECT is not set, takes normal path, fib_nh_common_init() is called. ip6_route_info_create_nh() still promotes it to reject afterward. nhc_pcpu_rth_output is allocated but unused, which is harmless. 3. Standalone nexthop object ("ip -6 nexthop add id 100 dev lo"): RTF_REJECT is not set, takes normal path, fib_nh_common_init() is called. nhc_pcpu_rth_output is properly allocated, fixing the crash when IPv4 routes reference this nexthop.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥5.3  –  <5.10.253
linuxlinux_kernel*≥5.11  –  <5.15.203
linuxlinux_kernel*≥5.16  –  <6.1.167
linuxlinux_kernel*≥6.2  –  <6.6.130
linuxlinux_kernel*≥6.7  –  <6.12.77
linuxlinux_kernel*≥6.13  –  <6.18.17
linuxlinux_kernel*≥6.19  –  <6.19.7
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/21ec92774d1536f71bdc90b0e3d052eff99cf093
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/607e68c1b7c5a30c795571be1906d716e989a644
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8650db85b4259d2885d2a80fbc2317ce24194133
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b299121e7453d23faddf464087dff513a495b4fc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b3b5a037d520afe3d5276e653bc0ff516bbda34c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b5062fc2150614c9ea8a611c2e0cb6e047ebfa3a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c11d7c56c2076ee9cd72004f1976fe0734df2ae9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f7c9f8e3607440fe39300efbaf46cf7b5eecb23f
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/21ec92774d1536f71bdc90b0e3d052eff99cf093
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/607e68c1b7c5a30c795571be1906d716e989a644
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8650db85b4259d2885d2a80fbc2317ce24194133
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b299121e7453d23faddf464087dff513a495b4fc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b3b5a037d520afe3d5276e653bc0ff516bbda34c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b5062fc2150614c9ea8a611c2e0cb6e047ebfa3a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c11d7c56c2076ee9cd72004f1976fe0734df2ae9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f7c9f8e3607440fe39300efbaf46cf7b5eecb23f
    Patch