{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "aaa5f515b16b6b3e137779ffb4c9558bb58c1e75"
            },
            {
              "fixed": "e5ba3017e46f275ad347e762e8eecacec5efa41d"
            },
            {
              "fixed": "160d3f0d7a556ceae505dcab521a37057b4ce28f"
            },
            {
              "fixed": "62c719203cb521b64fab74da94a81bdde5c18808"
            },
            {
              "fixed": "a6450f7cfae57b382cbaf66a577765c9a88b3c58"
            },
            {
              "fixed": "63d1c23764de2309cedbb779c75188d257a09d9b"
            },
            {
              "fixed": "d186e942365acece7c56d39da05dd63bf95b280a"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.0.0"
            },
            {
              "fixed": "6.1.183"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.148"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.97"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.40"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.1.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64542.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ndisc: fix NULL deref in accept_untracked_na()\n\naccept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev)\nand dereferences idev-\u003ecnf.accept_untracked_na without a NULL check,\neven though its only caller ndisc_recv_na() already fetched and\nNULL-checked idev for the same device.\n\nBoth reads of dev-\u003eip6_ptr run in the same RCU read-side critical\nsection, but a concurrent addrconf_ifdown() can clear dev-\u003eip6_ptr\nbetween them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown()\nwithout the synchronize_net() that orders the unregister path, so the\nre-fetch returns NULL and oopses:\n\n BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974)\n Read of size 4 at addr 0000000000000364\n Call Trace:\n  \u003cIRQ\u003e\n  ndisc_recv_na (net/ipv6/ndisc.c:974)\n  icmpv6_rcv (net/ipv6/icmp.c:1193)\n  ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479)\n  ip6_input_finish (net/ipv6/ip6_input.c:534)\n  ip6_input (net/ipv6/ip6_input.c:545)\n  ip6_mc_input (net/ipv6/ip6_input.c:635)\n  ipv6_rcv (net/ipv6/ip6_input.c:351)\n  \u003c/IRQ\u003e\n\nIt is reachable by an unprivileged user via a network namespace.\n\nPass the caller's already validated idev instead of re-fetching it; the\nidev stays alive for the whole RCU critical section, so it is safe even\nafter dev-\u003eip6_ptr has been cleared.",
  "id": "CVE-2026-64542",
  "modified": "2026-08-21T03:30:23.978999414Z",
  "published": "2026-07-27T20:10:34.994Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/160d3f0d7a556ceae505dcab521a37057b4ce28f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/62c719203cb521b64fab74da94a81bdde5c18808"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/63d1c23764de2309cedbb779c75188d257a09d9b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a6450f7cfae57b382cbaf66a577765c9a88b3c58"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d186e942365acece7c56d39da05dd63bf95b280a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e5ba3017e46f275ad347e762e8eecacec5efa41d"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64542.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64542"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "ipv6: ndisc: fix NULL deref in accept_untracked_na()"
}