CVE-2026-23442
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL when the device has no IPv6 configuration (e.g. MTU < IPV6_MIN_MTU or after NETDEV_UNREGISTER). Add NULL checks for idev returned by __in6_dev_get() in both seg6_hmac_validate_skb() and ipv6_srh_rcv() to prevent potential NULL pointer dereferences.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.12%• Percentile: 2%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- chainguard•hyperv-daemons-6.18
all
- chainguard•linux-aws-6.12
< 6.12.85-r0
- chainguard•linux-aws-6.18
all
- chainguard•linux-aws-6.18-boot-installed
all
- chainguard•linux-aws-6.18-bootc
all
- chainguard•linux-aws-6.18-bootc-boot-installed
all
- chainguard•linux-aws-6.18-fips-boot-installed
all
- chainguard•linux-aws-6.18-headers
all
- chainguard•linux-aws-6.18-modules
all
- chainguard•linux-azure-6.12
< 6.12.85-r0
- chainguard•linux-azure-6.18
all
- chainguard•linux-azure-6.18-boot-installed
all
- chainguard•linux-azure-6.18-fips-boot-installed
all
- chainguard•linux-azure-6.18-headers
all
- chainguard•linux-azure-6.18-modules
all
- chainguard•linux-desktop-6.18
all
- chainguard•linux-desktop-6.18-bootc
all
- chainguard•linux-desktop-6.18-bootc-boot-installed
all
- chainguard•linux-desktop-6.18-headers
all
- chainguard•linux-desktop-6.18-modules
all
- chainguard•linux-firecracker-6.18
all
- chainguard•linux-gcp-6.12
< 6.12.85-r0
- chainguard•linux-gcp-6.18
< 6.18.31-r0
- chainguard•linux-gcp-6.18-bootc
< 6.18.31-r0
- chainguard•linux-gcp-6.18-bootc-boot-installed
< 6.18.38-r2
- chainguard•linux-qemu-6.12
< 6.12.85-r0
- chainguard•linux-qemu-6.18
< 6.18.31-r0
- chainguard•linux-qemu-6.18-bootc
< 6.18.31-r0
- chainguard•linux-qemu-6.18-bootc-boot-installed
< 6.18.38-r2
- chainguard•linux-qemu-melange
< 0
- chainguard•linux-vmware-6.12
< 6.12.85-r0
- chainguard•linux-vmware-6.18
all
- chainguard•linux-vmware-6.18-boot-installed
all
- chainguard•linux-vmware-6.18-fips-boot-installed
all
- chainguard•linux-vmware-6.18-headers
all
- chainguard•linux-vmware-6.18-modules
all
- debian•linux
< 5.10.259-1 | < 6.1.176-1 | < 6.12.85-1 | < 6.19.10-1
- debian•linux-6.1
< 6.1.176-1~deb11u1
- ubuntu•linux
all | < 5.15.0-186.196 | < 6.8.0-136.136 | all
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
all | < 5.15.0-1112.119 | < 6.8.0-1061.64 | all
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1112.119~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.14
all
Showing first 50 affected entries in server-rendered view.
References (38)
- https://git.kernel.org/stable/c/a25853c9feea7bbf31d157ff6e004d2d3b4f7f13
- https://git.kernel.org/stable/c/06413793526251870e20402c39930804f14d59c0
- https://git.kernel.org/stable/c/bc9843c39f9932a8b36efd1d362ea00bb88e4e78
- https://git.kernel.org/stable/c/50352fc103928e10e8729abc79a0d05abef26c4d
- https://git.kernel.org/stable/c/c5cedee5d97382176573bbe21e1724e737a5eb64
- https://git.kernel.org/stable/c/0348fa0ada37cef7c6b5ab2a428bb2c6aee784e4
- https://git.kernel.org/stable/c/83d705d35e583cb1b1eacf196dfe7b77d442018e
- https://git.kernel.org/stable/c/d1bd8b9edc6752d10f84d28ff64f842401ce336d
- https://ubuntu.com/security/CVE-2026-23442
- https://www.cve.org/CVERecord?id=CVE-2026-23442
- https://git.kernel.org/linus/06413793526251870e20402c39930804f14d59c0
- https://ubuntu.com/security/notices/USN-8567-1
- https://ubuntu.com/security/notices/USN-8574-1
- https://ubuntu.com/security/notices/USN-8575-1
- https://ubuntu.com/security/notices/USN-8576-1
- https://ubuntu.com/security/notices/USN-8574-2
- https://ubuntu.com/security/notices/USN-8595-1
- https://ubuntu.com/security/notices/USN-8596-1
- https://ubuntu.com/security/notices/USN-8575-2
- https://ubuntu.com/security/notices/USN-8576-2
- https://ubuntu.com/security/notices/USN-8597-1
- https://ubuntu.com/security/notices/USN-8595-2
- https://ubuntu.com/security/notices/USN-8606-1
- https://ubuntu.com/security/notices/USN-8607-1
- https://ubuntu.com/security/notices/USN-8608-1
- https://ubuntu.com/security/notices/USN-8609-1
- https://ubuntu.com/security/notices/USN-8575-3
- https://ubuntu.com/security/notices/USN-8610-1
- https://ubuntu.com/security/notices/USN-8574-3
- https://ubuntu.com/security/notices/USN-8595-3
- https://ubuntu.com/security/notices/USN-8619-1
- https://ubuntu.com/security/notices/USN-8620-1
- https://ubuntu.com/security/notices/USN-8620-2
- https://ubuntu.com/security/notices/USN-8620-3
- https://ubuntu.com/security/notices/USN-8620-4
- https://security-tracker.debian.org/tracker/CVE-2026-23442
- https://ubuntu.com/security/notices/USN-8665-1
- https://ubuntu.com/security/notices/USN-8668-1