CVE-2026-80646 PUBLISHED

ipv6: guard against possible NULL deref in __in6_dev_stats_get()

Assigner: Linux
Reserved: 26.08.2026 Published: 28.08.2026 Updated: 28.08.2026

In the Linux kernel, the following vulnerability has been resolved:

ipv6: guard against possible NULL deref in __in6_dev_stats_get()

dev_get_by_index_rcu() could return NULL if the original physical device is unregistered.

Found by Sashiko.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f to a23f2c68c6635e41404f189f8f7ae910738cebdb (excl.)
  • affected from e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f to e14db43677946bf2095febd294bb3c13ab375ab7 (excl.)
  • affected from e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f to 1a4adfbeb47a212a64539137411f1ca168474d33 (excl.)
  • affected from e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f to 1e3db30a88815bae6e9d5db6f64ac735e615a07e (excl.)
  • affected from e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f to 952426a83ca75cea25c09d58944abafaa3ebd242 (excl.)
  • affected from e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f to 0db1949084e85a72d174a7dea3259b94fe5a9305 (excl.)
  • affected from e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f to fc920c0659cdea5afd8721c1155a51564859e075 (excl.)
  • affected from e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f to 507541c2a8eeb76c02bd2511958f73a8cfa3e1bc (excl.)
  • Version a24963500a4ec921ce9c2597e0a584e44513afae is affected
  • affected from 4.19.291 to 4.20 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.2 is affected
  • unaffected from 0 to 5.2 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.97 to 6.12.* (incl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References