← All Advisories

Linux Kernel IPv6 FIB6 Walk Reuses a Stale Position Index Across Hash Chain Batches During a Multi-Batch Netlink Dump, Triggering a NULL Dereference in fib6_walk_continue

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-72392

Key Details

CVECVE-2026-72392

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump

inet6_dump_fib() saves its progress in cb->args[1] as a positional

index within the current hash chain. Between batches, a concurrent

fib6_new_table() can insert a new table at the chain head, shifting

all existing entries. The saved index then lands on a different

table, causing fib6_dump_table() to set w->root to the wrong table

while w->node still points into the previous one.

fib6_walk_continue() dereferences w->node->parent (NULL) and panics:

BUG: kernel NULL pointer dereference, address: 0000000000000008

RIP: 0010:fib6_walk_continue+0x6e/0x170

Call Trace:

<TASK>

fib6_dump_table.isra.0+0xc5/0x240

inet6_dump_fib+0xf6/0x420

rtnl_dumpit+0x30/0xa0

netlink_dump+0x15b/0x460

netlink_recvmsg+0x1d6/0x2a0

____sys_recvmsg+0x17a/0x190

Fix by storing tb->tb6_id in cb->args[1] instead of a positional

index. On resume, skip entries until the id matches; a concurrent

head-insert can never match the saved id, so the walker always

resumes on the correct table. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-72392
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-72392