Null Dereference Vulnerability in Linux Kernel MPLS Component
CVE-2026-64569
What is CVE-2026-64569?
A vulnerability exists in the Linux kernel related to the MPLS component, specifically in the function mpls_valid_fib_dump_req(). In builds with CONFIG_INET disabled, this function improperly handles a missing attribute, leading to a null pointer dereference. An unprivileged user can exploit this scenario to trigger a crash in the kernel via an RTM_GETROUTE request. The issue occurs when the RTA_OIF attribute is not present, allowing for a potential denial of service. The vulnerability has been addressed in recent updates, emphasizing the importance of keeping systems up to date to mitigate such risks.
Affected Version(s)
Linux 196cfebf897266c3450519e916bab9daff74e52c
Linux 196cfebf897266c3450519e916bab9daff74e52c
Linux 196cfebf897266c3450519e916bab9daff74e52c < 5f6e7b32bd1fbde10fd31a4143260735ea535b8a