{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.187-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.101-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.101-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n  On CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed attribute table itself instead of calling ip_valid_fib_dump_req(). The RTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is present, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no RTA_OIF hits a NULL dereference.  RTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without CAP_NET_ADMIN, so an unprivileged user can trigger it.    Oops: general protection fault, probably for non-canonical address         0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI   KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]   RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)   Call Trace:    mpls_dump_routes (net/mpls/af_mpls.c:2236)    netlink_dump (net/netlink/af_netlink.c:2331)    __netlink_dump_start (net/netlink/af_netlink.c:2446)    rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)    netlink_rcv_skb (net/netlink/af_netlink.c:2556)    netlink_unicast (net/netlink/af_netlink.c:1345)    netlink_sendmsg (net/netlink/af_netlink.c:1900)    __sock_sendmsg (net/socket.c:790)    ____sys_sendmsg (net/socket.c:2684)    ___sys_sendmsg (net/socket.c:2738)    __sys_sendmsg (net/socket.c:2770)    do_syscall_64 (arch/x86/entry/syscall_64.c:94)    entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)  Skip unset attributes, as ip_valid_fib_dump_req() does.",
  "id": "DEBIAN-CVE-2026-64569",
  "modified": "2026-09-14T16:47:30.094874099Z",
  "published": "2026-08-05T08:16:36.547Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64569"
    }
  ],
  "upstream": [
    "CVE-2026-64569"
  ]
}