Null Pointer Dereference in Linux Kernel Netfilter Component
CVE-2026-98379

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-98379?

A vulnerability in the Linux kernel's netfilter component can lead to a NULL pointer dereference when an unprivileged user manipulates the routing table using the rtnetlink interface. This occurs when the 'ip6_route_lookup()' function mistakenly returns an error-free route with no associated inet6_dev, particularly under specific network conditions. If an external nexthop device's MTU is set below the minimum for IPv6, it can cause the inet6_dev to be deregistered. The flaw allows an attacker to induce a considerable kernel panic, which can disrupt normal operations and pose significant risks to system integrity.

Affected Version(s)

Linux e26f9a480fb6c1b614660e824d69a74e2ce990f3

Linux e26f9a480fb6c1b614660e824d69a74e2ce990f3 < 1681ab6dd1271f2f36047490793b78b1848bbcc9

Linux e26f9a480fb6c1b614660e824d69a74e2ce990f3 < 65487e9e99431ffcf05024a817f51ee4e3bd9b47

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.