CVE Database
/

CVE-2026-43101

Back to search

CVE-2026-43101

Published: May 6, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() We need to check __in6_dev_get() for possible NULL value, as suggested by Yiming Qian. Also add skb_dst_dev_rcu() instead of skb_dst_dev(), and two missing READ_ONCE(). Note that @dev can't be NULL.

VendorProductVersions

Linux

Linux

affected
9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 - < 4198aab6f000b4febb18ea820fea20634dd789c7
affected
9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 - < 3719c234fa94c37c955b1ecd3742ef280ec135e6
affected
9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 - < 4e65a8b8daa18d63255ec58964dd192c7fdd9f8b

Linux

Linux

affected
5.15
unaffected
0 - < 5.15
unaffected
6.18.24 - <= 6.18.*
unaffected
6.19.14 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now