cbcvebase.
CVE-2026-23381
published 2026-03-25

CVE-2026-23381: In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled When booting with the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never initialized because inet6_init() exits before ndisc_init() is called which initializes it. Then, if neigh_suppress is enabled and an ICMPv6 Neighbor Discovery packet reaches the bridge, br_do_suppress_nd() will dereference ipv6_stub->nd_tbl which is NULL, passing it to neigh_lookup(). This causes a kernel NULL pointer dereference. BUG: kernel NULL pointer dereference, address: 0000000000000268 Oops: 0000 [#1] PREEMPT SMP NOPTI [...] RIP: 0010:neigh_lookup+0x16/0xe0 [...] Call Trace: ? neigh_lookup+0x16/0xe0 br_do_suppress_nd+0x160/0x290 [bridge] br_handle_frame_finish+0x500/0x620 [bridge] br_handle_frame+0x353/0x440 [bridge] __netif_receive_skb_core.constprop.0+0x298/0x1110 __netif_receive_skb_one_core+0x3d/0xa0 process_backlog+0xa0/0x140 __napi_poll+0x2c/0x170 net_rx_action+0x2c4/0x3a0 handle_softirqs+0xd0/0x270 do_softirq+0x3f/0x60 Fix this by replacing IS_ENABLED(IPV6) call with ipv6_mod_enabled() in the callers. This is in essence disabling NS/NA suppression when IPv6 is disabled.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= ed842faeb2bd49256f00485402f3113205f91d30 < a9d712ccfeef737c0e700a4b5b98f310e07b6b60a9d712ccfeef737c0e700a4b5b98f310e07b6b60
linuxlinux>= ed842faeb2bd49256f00485402f3113205f91d30 < a5c56e65b685360dd3f2278aeff8c21061feb665a5c56e65b685360dd3f2278aeff8c21061feb665
linuxlinux>= ed842faeb2bd49256f00485402f3113205f91d30 < 7a894eb5de246d79f13105c55a67381039a24d447a894eb5de246d79f13105c55a67381039a24d44
linuxlinux>= ed842faeb2bd49256f00485402f3113205f91d30 < a12cdaa3375f0bd3c8f4e564be7c143529abfe5ba12cdaa3375f0bd3c8f4e564be7c143529abfe5b
linuxlinux>= ed842faeb2bd49256f00485402f3113205f91d30 < aa73deb3b6b730ec280d45b3f423bfa9e17bc122aa73deb3b6b730ec280d45b3f423bfa9e17bc122
linuxlinux>= ed842faeb2bd49256f00485402f3113205f91d30 < 33dec6f10777d5a8f71c0a200f690da5ae3c2e5533dec6f10777d5a8f71c0a200f690da5ae3c2e55
linuxlinux>= ed842faeb2bd49256f00485402f3113205f91d30 < 20ef5c25422f97dd09d751e5ae6c18406cdc78e620ef5c25422f97dd09d751e5ae6c18406cdc78e6
linuxlinux>= ed842faeb2bd49256f00485402f3113205f91d30 < e5e890630533bdc15b26a34bb8e7ef539bdf1322e5e890630533bdc15b26a34bb8e7ef539bdf1322
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 4.15.0 < 6.1.1676.1.167
linuxlinux_kernel>= 4.15.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.