cbcvebase.
CVE-2026-23304
published 2026-03-25

CVE-2026-23304: In the Linux kernel, the following vulnerability has been resolved: ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() l3mdev_master_dev_rcu() can return…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() l3mdev_master_dev_rcu() can return NULL when the slave device is being un-slaved from a VRF. All other callers deal with this, but we lost the fallback to loopback in ip6_rt_pcpu_alloc() -> ip6_rt_get_dev_rcu() with commit 4832c30d5458 ("net: ipv6: put host and anycast routes on device with address"). KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f] RIP: 0010:ip6_rt_pcpu_alloc (net/ipv6/route.c:1418) Call Trace: ip6_pol_route (net/ipv6/route.c:2318) fib6_rule_lookup (net/ipv6/fib6_rules.c:115) ip6_route_output_flags (net/ipv6/route.c:2607) vrf_process_v6_outbound (drivers/net/vrf.c:437) I was tempted to rework the un-slaving code to clear the flag first and insert synchronize_rcu() before we remove the upper. But looks like the explicit fallback to loopback_dev is an established pattern. And I guess avoiding the synchronize_rcu() is nice, too.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 4832c30d5458387ff2533ff66fbde26ad8bb5a2d < d542e2ac7f9e288d49735be0775611547ca4e0eed542e2ac7f9e288d49735be0775611547ca4e0ee
linuxlinux>= 4832c30d5458387ff2533ff66fbde26ad8bb5a2d < a73fe9f4ae84a239d5b2686f47a58c158aee2eb4a73fe9f4ae84a239d5b2686f47a58c158aee2eb4
linuxlinux>= 4832c30d5458387ff2533ff66fbde26ad8bb5a2d < 4a48fe59f29f673a3d042d679f26629a9c3e29d44a48fe59f29f673a3d042d679f26629a9c3e29d4
linuxlinux>= 4832c30d5458387ff2533ff66fbde26ad8bb5a2d < 581800298313c9fd75e94985e6d37d21b7e35d34581800298313c9fd75e94985e6d37d21b7e35d34
linuxlinux>= 4832c30d5458387ff2533ff66fbde26ad8bb5a2d < 3310fc11fc47387d1dd4759b0bc961643ea11c7f3310fc11fc47387d1dd4759b0bc961643ea11c7f
linuxlinux>= 4832c30d5458387ff2533ff66fbde26ad8bb5a2d < 0b5a7826020706057cc5a9d9009e667027f221ee0b5a7826020706057cc5a9d9009e667027f221ee
linuxlinux>= 4832c30d5458387ff2533ff66fbde26ad8bb5a2d < ae88c8256547b63980770a9ea7be73a15900d27eae88c8256547b63980770a9ea7be73a15900d27e
linuxlinux>= 4832c30d5458387ff2533ff66fbde26ad8bb5a2d < 2ffb4f5c2ccb2fa1c049dd11899aee7967deef5a2ffb4f5c2ccb2fa1c049dd11899aee7967deef5a
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 4.14 < 5.10.2535.10.253
linuxlinux_kernel>= 4.14.0 < 6.1.1676.1.167
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
linuxlinux_kernel>= 6.7.0 < 6.12.776.12.77

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.