cbcvebase.
CVE-2026-22988
published 2026-01-23

CVE-2026-22988: In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not change skb->head arp_create() is the only…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.5th percentile
In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not change skb->head arp_create() is the only dev_hard_header() caller making assumption about skb->head being unchanged. A recent commit broke this assumption. Initialize @arp pointer after dev_hard_header() call.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux>= 1717357007db150c2d703f13f5695460e960f26c < 029935507d0af6553c45380fbf6feecf756fd226029935507d0af6553c45380fbf6feecf756fd226
linuxlinux>= 17e7386234f740f3e7d5e58a47b5847ea34c3bc2 < e432dbff342b95fe44645f9a90fcf333c80f4b5ee432dbff342b95fe44645f9a90fcf333c80f4b5e
linuxlinux>= 41a1a3140aff295dee8063906f70a514548105e8 < 393525dee5c39acff8d6705275d7fcaabcfb7f0a393525dee5c39acff8d6705275d7fcaabcfb7f0a
linuxlinux>= 5fe210533e3459197eabfdbf97327dacbdc04d60 < dd6ccec088adff4bdf33e2b2dd102df20a7128fadd6ccec088adff4bdf33e2b2dd102df20a7128fa
linuxlinux>= 6.1.160 < 6.1.1616.1.161
linuxlinux>= 6.12.64 < 6.12.666.12.66
linuxlinux>= 6.18.4 < 6.18.66.18.6
linuxlinux>= 6.6.120 < 6.6.1216.6.121
linuxlinux>= 91a2b25be07ce1a7549ceebbe82017551d2eec92 < 949647e7771a4a01963fe953a96d81fba7acecf3949647e7771a4a01963fe953a96d81fba7acecf3
linuxlinux>= adee129db814474f2f81207bd182bf343832a52e < 70bddc16491ef4681f3569b3a2c80309a3edcdd170bddc16491ef4681f3569b3a2c80309a3edcdd1
linuxlinux>= db5b4e39c4e63700c68a7e65fc4e1f1375273476 < c92510f5e3f82ba11c95991824a41e59a9c5ed81c92510f5e3f82ba11c95991824a41e59a9c5ed81
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 6.12.64 < 6.12.666.12.66
linuxlinux_kernel>= 6.18.4 < 6.18.66.18.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.