SB20260905100 - NULL pointer dereference in Linux kernel xfrm
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-80846)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the handle_esp function when processing queued ESP-in-TCP data after its ingress device has been removed. A remote attacker can send ESP-in-TCP records to cause a denial of service.
The condition can occur during veth or network namespace teardown.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/239d0f71af09dc2029fd4d730cb24b8c83aaa43a
- https://git.kernel.org/stable/c/2dd1609cadff46c4b20ce53b91ab9cce1380456a
- https://git.kernel.org/stable/c/328e40aa774b446969c69b654c52a051a95af8a1
- https://git.kernel.org/stable/c/6af5cdb03819a5ce6e945992635c6c5e91045367
- https://git.kernel.org/stable/c/7911e0236616487b89db6bd3ba3f408abd10eb23
- https://git.kernel.org/stable/c/943d95233b8b4a88994e244fcf466f8c403d63f1
- https://git.kernel.org/stable/c/c296d25efbc840be24de83f56d43bc47e714ace9
- https://git.kernel.org/stable/c/e1d7c5ac1c246ce5775f604515de0a59fbf2116e
- https://git.kernel.org/stable/c/f00235f9d12301183d61f75fbe4105506f3e5140