CVE-2026-23442: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL when the device has no IPv6 configuration (e.g. MTU < IPV6_MIN_MTU or after NETDEV_UNREGISTER). Add NULL checks for idev returned by __in6_dev_get() in both seg6_hmac_validate_skb() and ipv6_srh_rcv() to prevent potential NULL pointer dereferences.

Affected products

  • Linux Linux Kernel: from 4.10.1, before 6.12.83 (fixed in 6.12.83); from 6.13, before 6.19.10 (fixed in 6.19.10); version 4.10 only; version 7.0 only

Published 2026-04-03. Last modified 2026-07-24.