{"id":"CVE-2026-64542","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ndisc: fix NULL deref in accept_untracked_na()\n\naccept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev)\nand dereferences idev->cnf.accept_untracked…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ndisc: fix NULL deref in accept_untracked_na()\n\naccept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev)\nand dereferences idev->cnf.accept_untracked…","severity":"none","published":"2026-07-27","updated":"2026-08-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64542","references":[{"url":"https://git.kernel.org/stable/c/160d3f0d7a556ceae505dcab521a37057b4ce28f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62c719203cb521b64fab74da94a81bdde5c18808","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63d1c23764de2309cedbb779c75188d257a09d9b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6450f7cfae57b382cbaf66a577765c9a88b3c58","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d186e942365acece7c56d39da05dd63bf95b280a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00173,"epssPercentile":0.06998,"ingestedAt":"2026-08-03T10:24:20.734Z","slug":"CVE-2026-64542","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ndisc: fix NULL deref in accept_untracked_na()\n\naccept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev)\nand dereferences idev->cnf.accept_untracked_na without a NULL check,\neven though its only caller ndisc_recv_na() already fetched and\nNULL-checked idev for the same device.\n\nBoth reads of dev->ip6_ptr run in the same RCU read-side critical\nsection, but a concurrent addrconf_ifdown() can clear dev->ip6_ptr\nbetween them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown()\nwithout the synchronize_net() that orders the unregister path, so the\nre-fetch returns NULL and oopses:\n\n BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974)\n Read of size 4 at addr 0000000000000364\n Call Trace:\n  <IRQ>\n  ndisc_recv_na (net/ipv6/ndisc.c:974)\n  icmpv6_rcv (net/ipv6/icmp.c:1193)\n  ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479)\n  ip6_input_finish (net/ipv6/ip6_input.c:534)\n  ip6_input (net/ipv6/ip6_input.c:545)\n  ip6_mc_input (net/ipv6/ip6_input.c:635)\n  ipv6_rcv (net/ipv6/ip6_input.c:351)\n  </IRQ>\n\nIt is reachable by an unprivileged user via a network namespace.\n\nPass the caller's already validated idev instead of re-fetching it; the\nidev stays alive for the whole RCU critical section, so it is safe even\nafter dev->ip6_ptr has been cleared.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}