cbcvebase.
CVE-2026-23442
published 2026-04-03

CVE-2026-23442: In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL when the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL when the device has no IPv6 configuration (e.g. MTU < IPV6_MIN_MTU or after NETDEV_UNREGISTER). Add NULL checks for idev returned by __in6_dev_get() in both seg6_hmac_validate_skb() and ipv6_srh_rcv() to prevent potential NULL pointer dereferences.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= 1ababeba4a21f3dba3da3523c670b207fb2feb62 < 0348fa0ada37cef7c6b5ab2a428bb2c6aee784e40348fa0ada37cef7c6b5ab2a428bb2c6aee784e4
linuxlinux>= 1ababeba4a21f3dba3da3523c670b207fb2feb62 < 83d705d35e583cb1b1eacf196dfe7b77d442018e83d705d35e583cb1b1eacf196dfe7b77d442018e
linuxlinux>= 1ababeba4a21f3dba3da3523c670b207fb2feb62 < d1bd8b9edc6752d10f84d28ff64f842401ce336dd1bd8b9edc6752d10f84d28ff64f842401ce336d
linuxlinux>= 1ababeba4a21f3dba3da3523c670b207fb2feb62 < 50352fc103928e10e8729abc79a0d05abef26c4d50352fc103928e10e8729abc79a0d05abef26c4d
linuxlinux>= 1ababeba4a21f3dba3da3523c670b207fb2feb62 < bc9843c39f9932a8b36efd1d362ea00bb88e4e78bc9843c39f9932a8b36efd1d362ea00bb88e4e78
linuxlinux>= 1ababeba4a21f3dba3da3523c670b207fb2feb62 < c5cedee5d97382176573bbe21e1724e737a5eb64c5cedee5d97382176573bbe21e1724e737a5eb64
linuxlinux>= 1ababeba4a21f3dba3da3523c670b207fb2feb62 < a25853c9feea7bbf31d157ff6e004d2d3b4f7f13a25853c9feea7bbf31d157ff6e004d2d3b4f7f13
linuxlinux>= 1ababeba4a21f3dba3da3523c670b207fb2feb62 < 06413793526251870e20402c39930804f14d59c006413793526251870e20402c39930804f14d59c0
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 4.10.1 < 6.12.836.12.83
linuxlinux_kernel>= 6.13 < 6.19.106.19.10
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_redhat6.5MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.