PT-2026-30137 · Linux · Linux Kernel

Published

2026-04-03

·

Updated

2026-05-26

·

CVE-2026-23442

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw where the in6 dev get() function can return NULL when a device lacks IPv6 configuration, such as when the MTU is less than the minimum IPv6 MTU or after device unregistration. This can lead to NULL pointer dereferences in seg6 hmac validate skb() and ipv6 srh rcv() functions when processing SRv6 paths.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-23442
ECHO-C55E-EF7D-8505
OESA-2026-2172
OESA-2026-2176
OESA-2026-2232

Affected Products

Linux Kernel