cbcvebase.
CVE-2026-52998
published 2026-06-24

CVE-2026-52998: In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl()…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.51%
40.1th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl() function accessed skb->dev to perform a local interface address lookup without verifying that the device pointer was valid. Additionally, the implementation utilized an in_dev_for_each_ifa_rcu loop to match the packet source address against local interface addresses. It assumed that packets from the same subnet should not see a decrement on the initial TTL. A packet might appear it is from the same subnet but it actually isn't especially in modern environments with containers and virtual switching. Remove the device dereference and interface loop. Replace the logic with a switch statement that evaluates the TTL according to the ttl_check.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < f4de0777e4554a7de19c920accde6319dd530782f4de0777e4554a7de19c920accde6319dd530782
linuxlinux>= 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < c996a90f3071cf43683e5423da31aadbe002b8b4c996a90f3071cf43683e5423da31aadbe002b8b4
linuxlinux>= 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < edc806f9122961f0d3819f7c69c14cccde31f277edc806f9122961f0d3819f7c69c14cccde31f277
linuxlinux>= 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 5d05de2f0928d81309a815ecc76d1a3ad72cbc165d05de2f0928d81309a815ecc76d1a3ad72cbc16
linuxlinux>= 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 95be653a76793856ff8b2d8bd82c2943c23f5ca895be653a76793856ff8b2d8bd82c2943c23f5ca8
linuxlinux>= 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 79b90a96688e521771fa6ed3dc7864b76b8df29379b90a96688e521771fa6ed3dc7864b76b8df293
linuxlinux>= 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 83fc5dd63455a779ea2dd0f7ffee3c920919d80b83fc5dd63455a779ea2dd0f7ffee3c920919d80b
linuxlinux>= 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 711987ba281fd806322a7cd244e98e2a81903114711987ba281fd806322a7cd244e98e2a81903114
linuxlinux_kernel
linuxlinux_kernel>= 2.6.31 < 5.10.2585.10.258
linuxlinux_kernel>= 5.11 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.336.18.33
linuxlinux_kernel>= 6.19 < 7.0.107.0.10
linuxlinux_kernel>= 6.2 < 6.6.1416.6.141
linuxlinux_kernel>= 6.7 < 6.12.916.12.91
ubuntulinux
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-hwe-7.0
ubuntulinux-oem-7.0
ubuntulinux-realtime

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.0MEDIUM
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.