Re: [PATCH net v3] ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
From: Simon Horman
Date: Thu Aug 20 2026 - 08:28:56 EST
On Mon, Aug 17, 2026 at 03:26:44PM +0200, Andrea Mayer wrote:
> ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL
> check when reading idev->cnf.rpl_seg_enabled.
>
> When the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears
> dev->ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev
> check in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with
> dev->ip6_ptr already NULL.
>
> Reproduced by flooding the receiving interface with ping6 traffic while
> flapping its MTU between 1500 and 1200:
>
> BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070
> Read of size 4 at addr 00000000000006b4 by task ping6/394
>
> CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)
> Call Trace:
> <IRQ>
> kasan_report+0xc6/0x100
> ipv6_rpl_srh_rcv+0xb3/0x1070
> ip6_protocol_deliver_rcu+0x759/0x9a0
> ip6_input_finish+0xa8/0x1b0
> ip6_input+0xe1/0x490
> ipv6_rcv+0x33d/0x460
> __netif_receive_skb_one_core+0xd6/0x130
> process_backlog+0x2cc/0xa00
> __napi_poll.constprop.0+0x56/0x270
> net_rx_action+0x327/0x730
> handle_softirqs+0x11e/0x630
> do_softirq+0xb3/0xf0
> </IRQ>
>
> Both ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from
> ipv6_rthdr_rcv(), which already has an idev lookup.
>
> Fix the NULL dereference on the RPL path by checking idev in
> ipv6_rthdr_rcv(), before it calls either function. The callees take idev as
> an argument and no longer call __in6_dev_get(), so the packet is now
> dropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.
>
> Fixes: 8610c7c6e3bd ("net: ipv6: add support for rpl sr exthdr")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Andrea Mayer <andrea.mayer@xxxxxxxxxxx>
> Tested-by: Xiang Mei <xmei5@xxxxxxx>
> ---
> v3:
> - move the idev NULL check into ipv6_rthdr_rcv() and use the same drop
> reason on the seg6 and RPL paths (David Ahern)
> - pass idev to ipv6_srh_rcv() and ipv6_rpl_srh_rcv(), and check it for
> NULL in ipv6_rthdr_rcv() only for the seg6 and RPL types
> - add Xiang Mei's Tested-by tag
> v2: https://lore.kernel.org/netdev/20260518140630.24280-1-andrea.mayer@xxxxxxxxxxx/
> - use SKB_DROP_REASON_IPV6DISABLED as drop reason (Eric Dumazet)
> v1: https://lore.kernel.org/netdev/20260428224816.11223-1-andrea.mayer@xxxxxxxxxxx/
Reviewed-by: Simon Horman <horms@xxxxxxxxxx>