{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.187-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.101-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.101-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  bonding: fix devconf_all NULL dereference when IPv6 is disabled  When booting with the 'ipv6.disable=1' parameter, the devconf_all is never initialized because inet6_init() exits before addrconf_init() is called which initializes it. bond_send_validate(), however, will still call bond_ns_send_all() even ipv6 is indeed disabled. It will lead to NULL derefence of net-\u003eipv6.devconf_all in ip6_pol_route().   BUG: kernel NULL pointer dereference, address: 000000000000000c  [...]  Workqueue: bond0 bond_arp_monitor [bonding]  RIP: 0010:ip6_pol_route+0x69/0x480  [...]  Call Trace:   \u003cTASK\u003e   ? srso_return_thunk+0x5/0x5f   ? __pfx_ip6_pol_route_output+0x10/0x10   fib6_rule_lookup+0xfe/0x260   ? wakeup_preempt+0x8a/0x90   ? srso_return_thunk+0x5/0x5f   ? srso_return_thunk+0x5/0x5f   ? sched_balance_rq+0x369/0x810   ip6_route_output_flags+0xd7/0x170   bond_ns_send_all+0xde/0x280 [bonding]   bond_ab_arp_probe+0x296/0x320 [bonding]   ? srso_return_thunk+0x5/0x5f   bond_activebackup_arp_mon+0xb4/0x2c0 [bonding]   process_one_work+0x196/0x370   worker_thread+0x1af/0x320   ? srso_return_thunk+0x5/0x5f   ? __pfx_worker_thread+0x10/0x10   kthread+0xe3/0x120   ? __pfx_kthread+0x10/0x10   ret_from_fork+0x199/0x260   ? __pfx_kthread+0x10/0x10   ret_from_fork_asm+0x1a/0x30   \u003c/TASK\u003e  Fix this by adding ipv6_mod_enabled() condition check in the caller.",
  "id": "DEBIAN-CVE-2026-68336",
  "modified": "2026-09-14T16:47:32.261126152Z",
  "published": "2026-08-10T13:20:23.990Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-68336"
    }
  ],
  "upstream": [
    "CVE-2026-68336"
  ]
}