CVE-2026-23277 — NULL Pointer Dereference in Linux
Severity
5.9MEDIUM
No vectorEPSS
0.0%
top 90.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 20
Description
In the Linux kernel, the following vulnerability has been resolved:
net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit
teql_master_xmit() calls netdev_start_xmit(skb, slave) to transmit
through slave devices, but does not update skb->dev to the slave device
beforehand.
When a gretap tunnel is a TEQL slave, the transmit path reaches
iptunnel_xmit() which saves dev = skb->dev (still pointing to teql0
master) and later calls iptunnel_xmit_stats(dev, pkt_len). This
…
Affected Packages3 packages
▶CVEListV5linux/linux039f50629b7f860f36644ed1f34b27da9aa62f43 — 57c153249143333bbf4ecf927bdf8aa2696ee397+6
🔴Vulnerability Details
4CVEList
▶
GHSA▶
GHSA-v66f-jqgm-8687: In the Linux kernel, the following vulnerability has been resolved:
net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit↗2026-03-20
OSV▶
CVE-2026-23277: In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit↗2026-03-20