Home

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL when the device has no IPv6 configuration (e.g. MTU < IPV6_MIN_MTU or after NETDEV_UNREGISTER). Add NULL checks for idev returned by __in6_dev_get() in both seg6_hmac_validate_skb() and ipv6_srh_rcv() to prevent potential NULL pointer dereferences.

PUBLISHED Reserved 2026-01-13 | Published 2026-04-03 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

1ababeba4a21f3dba3da3523c670b207fb2feb62 (git) before 50352fc103928e10e8729abc79a0d05abef26c4d
affected

1ababeba4a21f3dba3da3523c670b207fb2feb62 (git) before bc9843c39f9932a8b36efd1d362ea00bb88e4e78
affected

1ababeba4a21f3dba3da3523c670b207fb2feb62 (git) before c5cedee5d97382176573bbe21e1724e737a5eb64
affected

1ababeba4a21f3dba3da3523c670b207fb2feb62 (git) before a25853c9feea7bbf31d157ff6e004d2d3b4f7f13
affected

1ababeba4a21f3dba3da3523c670b207fb2feb62 (git) before 06413793526251870e20402c39930804f14d59c0
affected

Default status
affected

4.10
affected

Any version before 4.10
unaffected

6.6.136 (semver)
unaffected

6.12.83 (semver)
unaffected

6.18.25 (semver)
unaffected

6.19.10 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/50352fc103928e10e8729abc79a0d05abef26c4d

git.kernel.org/...c/bc9843c39f9932a8b36efd1d362ea00bb88e4e78

git.kernel.org/...c/c5cedee5d97382176573bbe21e1724e737a5eb64

git.kernel.org/...c/a25853c9feea7bbf31d157ff6e004d2d3b4f7f13

git.kernel.org/...c/06413793526251870e20402c39930804f14d59c0

cve.org (CVE-2026-23442)

nvd.nist.gov (CVE-2026-23442)

Download JSON