CVE-2026-80646: Linux

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ipv6: guard against possible NULL deref in __in6_dev_stats_get() dev_get_by_index_rcu() could return NULL if the original physical device is unregistered. Found by Sashiko.

Affected products

  • Linux Linux: from 4.19.291, before 4.20 (fixed in 4.20); from 5.2, before 5.10.261 (fixed in 5.10.261); from 5.11, before 5.15.212 (fixed in 5.15.212); from 5.16, before 6.1.178 (fixed in 6.1.178); from 6.2, before 6.6.145 (fixed in 6.6.145); from 6.7, before 6.12.97 (fixed in 6.12.97); …

Published 2026-08-28. Last modified 2026-08-29.