CVE-2026-64569
In the Linux kernel, the following vulnerability has been resolved:
mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
On CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed attribute table itself instead of calling ip_valid_fib_dump_req(). The RTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is present, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no RTA_OIF hits a NULL dereference.
RTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without CAP_NET_ADMIN, so an unprivileged user can trigger it.
Skip unset attributes, as ip_valid_fib_dump_req() does.
Detalles técnicos trazas, registros y código del informe original
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)
Call Trace:
mpls_dump_routes (net/mpls/af_mpls.c:2236)
netlink_dump (net/netlink/af_netlink.c:2331)
__netlink_dump_start (net/netlink/af_netlink.c:2446)
rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)
netlink_rcv_skb (net/netlink/af_netlink.c:2556)
netlink_unicast (net/netlink/af_netlink.c:1345)
netlink_sendmsg (net/netlink/af_netlink.c:1900)
__sock_sendmsg (net/socket.c:790)
____sys_sendmsg (net/socket.c:2684)
___sys_sendmsg (net/socket.c:2738)
__sys_sendmsg (net/socket.c:2770)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/03b5a2c29afc8e634924c75d6ee94140e70de88d
- https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502
- https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3
- https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a
- https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce
- https://git.kernel.org/stable/c/bfc1cb5d6a8308e493e307f1c823d2107abc0a47
- https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71
- https://git.kernel.org/stable/c/e796ce9ef4356dc7cbbaa8373843f77852f2814d
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64569",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"lessThan": "bfc1cb5d6a8308e493e307f1c823d2107abc0a47",
"versionType": "git"
},
{
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"lessThan": "03b5a2c29afc8e634924c75d6ee94140e70de88d",
"versionType": "git"
},
{
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"lessThan": "e796ce9ef4356dc7cbbaa8373843f77852f2814d",
"versionType": "git"
},
{
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"lessThan": "d6eee7cd078aaf9dd75efc801f6c9b608a37cd71",
"versionType": "git"
},
{
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"lessThan": "ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce",
"versionType": "git"
},
{
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"lessThan": "5f6e7b32bd1fbde10fd31a4143260735ea535b8a",
"versionType": "git"
},
{
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"lessThan": "06db79411a280707c7e4bf4b221ff4e664b51502",
"versionType": "git"
},
{
"status": "affected",
"version": "196cfebf897266c3450519e916bab9daff74e52c",
"lessThan": "56d96fededd61192cd7cc8d2b0f36adfd59036c3",
"versionType": "git"
}
],
"programFiles": [
"net/mpls/af_mpls.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/mpls/af_mpls.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-05T08:16:36.547",
"references": [
{
"url": "https://git.kernel.org/stable/c/03b5a2c29afc8e634924c75d6ee94140e70de88d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bfc1cb5d6a8308e493e307f1c823d2107abc0a47",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e796ce9ef4356dc7cbbaa8373843f77852f2814d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n Oops: general protection fault, probably for non-canonical address\n 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n Call Trace:\n mpls_dump_routes (net/mpls/af_mpls.c:2236)\n netlink_dump (net/netlink/af_netlink.c:2331)\n __netlink_dump_start (net/netlink/af_netlink.c:2446)\n rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n netlink_unicast (net/netlink/af_netlink.c:1345)\n netlink_sendmsg (net/netlink/af_netlink.c:1900)\n __sock_sendmsg (net/socket.c:790)\n ____sys_sendmsg (net/socket.c:2684)\n ___sys_sendmsg (net/socket.c:2738)\n __sys_sendmsg (net/socket.c:2770)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does."
}
],
"lastModified": "2026-08-19T17:20:16.777",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}