CVE-2026-43101: Linux Kernel
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() We need to check __in6_dev_get() for possible NULL value, as suggested by Yiming Qian. Also add skb_dst_dev_rcu() instead of skb_dst_dev(), and two missing READ_ONCE(). Note that @dev can't be NULL.
Affected products
- Linux Linux Kernel: from 5.15, before 6.18.24 (fixed in 6.18.24); from 6.19, before 6.19.14 (fixed in 6.19.14); version 7.0 only
Published 2026-05-06. Last modified 2026-06-17.