CVE-2026-23442

Source
https://cve.org/CVERecord?id=CVE-2026-23442
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23442.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23442
Downstream
Related
Published
2026-04-03T15:15:26.851Z
Modified
2026-06-18T03:55:37.295704962Z
Summary
ipv6: add NULL checks for idev in SRv6 paths
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv6: add NULL checks for idev in SRv6 paths

_in6devget() can return NULL when the device has no IPv6 configuration (e.g. MTU < IPV6MINMTU or after NETDEVUNREGISTER).

Add NULL checks for idev returned by _in6devget() in both seg6hmacvalidateskb() and ipv6srhrcv() to prevent potential NULL pointer dereferences.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23442.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1ababeba4a21f3dba3da3523c670b207fb2feb62
Fixed
0348fa0ada37cef7c6b5ab2a428bb2c6aee784e4
Fixed
83d705d35e583cb1b1eacf196dfe7b77d442018e
Fixed
d1bd8b9edc6752d10f84d28ff64f842401ce336d
Fixed
50352fc103928e10e8729abc79a0d05abef26c4d
Fixed
bc9843c39f9932a8b36efd1d362ea00bb88e4e78
Fixed
c5cedee5d97382176573bbe21e1724e737a5eb64
Fixed
a25853c9feea7bbf31d157ff6e004d2d3b4f7f13
Fixed
06413793526251870e20402c39930804f14d59c0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23442.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.136
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.83
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.25
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23442.json"