{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()  ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL check when reading idev-\u003ecnf.rpl_seg_enabled.  When the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears dev-\u003eip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev check in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with dev-\u003eip6_ptr already NULL.  Reproduced by flooding the receiving interface with ping6 traffic while flapping its MTU between 1500 and 1200:   BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070  Read of size 4 at addr 00000000000006b4 by task ping6/394   CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)  Call Trace:   \u003cIRQ\u003e   kasan_report+0xc6/0x100   ipv6_rpl_srh_rcv+0xb3/0x1070   ip6_protocol_deliver_rcu+0x759/0x9a0   ip6_input_finish+0xa8/0x1b0   ip6_input+0xe1/0x490   ipv6_rcv+0x33d/0x460   __netif_receive_skb_one_core+0xd6/0x130   process_backlog+0x2cc/0xa00   __napi_poll.constprop.0+0x56/0x270   net_rx_action+0x327/0x730   handle_softirqs+0x11e/0x630   do_softirq+0xb3/0xf0   \u003c/IRQ\u003e  Both ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from ipv6_rthdr_rcv(), which already has an idev lookup.  Fix the NULL dereference on the RPL path by checking idev in ipv6_rthdr_rcv(), before it calls either function. The callees take idev as an argument and no longer call __in6_dev_get(), so the packet is now dropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.",
  "id": "DEBIAN-CVE-2026-89561",
  "modified": "2026-09-14T08:47:35.294775121Z",
  "published": "2026-09-11T20:19:39.933Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89561"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89561"
  ]
}