CVE Database
/

CVE-2026-23442

Back to search

CVE-2026-23442

Published: Apr 3, 2026

Modified: Jun 1, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL when the device has no IPv6 configuration (e.g. MTU < IPV6_MIN_MTU or after NETDEV_UNREGISTER). Add NULL checks for idev returned by __in6_dev_get() in both seg6_hmac_validate_skb() and ipv6_srh_rcv() to prevent potential NULL pointer dereferences.

VendorProductVersions

Linux

Linux

affected
1ababeba4a21f3dba3da3523c670b207fb2feb62 - < 0348fa0ada37cef7c6b5ab2a428bb2c6aee784e4
affected
1ababeba4a21f3dba3da3523c670b207fb2feb62 - < 83d705d35e583cb1b1eacf196dfe7b77d442018e
affected
1ababeba4a21f3dba3da3523c670b207fb2feb62 - < d1bd8b9edc6752d10f84d28ff64f842401ce336d
affected
1ababeba4a21f3dba3da3523c670b207fb2feb62 - < 50352fc103928e10e8729abc79a0d05abef26c4d
affected
1ababeba4a21f3dba3da3523c670b207fb2feb62 - < bc9843c39f9932a8b36efd1d362ea00bb88e4e78

+3 more versions

Linux

Linux

affected
4.10
unaffected
0 - < 4.10
unaffected
5.10.258 - <= 5.10.*
unaffected
5.15.209 - <= 5.15.*
unaffected
6.1.175 - <= 6.1.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now