public inbox for netdev@vger.kernel.org
 help / color / mirror / Atom feed
* [BUG] Potential Null Pointer Dereference in nexthop_create_group Function
@ 2026-02-14 12:17 冯嘉仪
  2026-02-14 12:35 ` Eric Dumazet
  0 siblings, 1 reply; 5+ messages in thread
From: 冯嘉仪 @ 2026-02-14 12:17 UTC (permalink / raw)
  To: dsahern; +Cc: davem, edumazet, kuba, pabeni, netdev, linux-kernel

Dear Maintainer,

Our team recently developed a null-pointer-dereference (NPD) vulnerability detection tool, and we used it to scan the Linux Kernel (version 6.9.6). After manual review, we identified a potentially vulnerable code snippet that could lead to a null-pointer dereference bug. We would appreciate your expert insight to confirm whether this vulnerability could indeed pose a risk to the system.

Vulnerability Description:
File:  net/ipv4/nexthop.c
In the function nexthop_create_group, we found the following line of code:

if (!nexthop_get(nhe)) {

The issue arises because the nhe pointer may be passed as NULL in certain situations. The statement passes the nhe pointer to nexthop_get without any check, but nexthop_get might contain a dereference operation on the nhe pointer, which could result in a null-pointer dereference.

Proposed Fix:
To prevent the potential null-pointer dereference, we suggest adding a NULL check for the nhe pointer before attempting to pass the pointer to nexthop_get.

Request for Review:
We would appreciate your expert insight to confirm whether this vulnerability indeed poses a risk to the system, and if the proposed fix is appropriate. If there are reasons why this issue does not present a real risk (e.g., the NULL check is redundant or unnecessary), we would be grateful for clarification.

Thank you for your time and consideration.

^ permalink raw reply	[flat|nested] 5+ messages in thread
[parent not found: <tencent_60BB14B216A3DFF94F6928CE@qq.com>]

end of thread, other threads:[~2026-02-16 10:17 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-02-14 12:17 [BUG] Potential Null Pointer Dereference in nexthop_create_group Function 冯嘉仪
2026-02-14 12:35 ` Eric Dumazet
2026-02-14 12:37   ` Eric Dumazet
2026-02-14 16:16     ` David Ahern
     [not found] <tencent_60BB14B216A3DFF94F6928CE@qq.com>
2026-02-16 10:17 ` Paolo Abeni

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox