CVE-2026-23277NULL Pointer Dereference in Linux

Severity
5.9MEDIUM
No vector
EPSS
0.0%
top 90.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 20

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit teql_master_xmit() calls netdev_start_xmit(skb, slave) to transmit through slave devices, but does not update skb->dev to the slave device beforehand. When a gretap tunnel is a TEQL slave, the transmit path reaches iptunnel_xmit() which saves dev = skb->dev (still pointing to teql0 master) and later calls iptunnel_xmit_stats(dev, pkt_len). This

Affected Packages3 packages

Linuxlinux/linux_kernel4.5.06.1.167+4
Debianlinux/linux_kernel< 6.19.10-1
CVEListV5linux/linux039f50629b7f860f36644ed1f34b27da9aa62f4357c153249143333bbf4ecf927bdf8aa2696ee397+6

🔴Vulnerability Details

4
CVEList
net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit2026-03-20
OSV
net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit2026-03-20
GHSA
GHSA-v66f-jqgm-8687: In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit2026-03-20
OSV
CVE-2026-23277: In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit2026-03-20

📋Vendor Advisories

3
Red Hat
kernel: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit2026-03-20
Microsoft
net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit2026-03-10
Debian
CVE-2026-23277: linux - In the Linux kernel, the following vulnerability has been resolved: net/sched: ...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23277 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23277 — NULL Pointer Dereference in Linux | cvebase