NULL pointer dereference in Linux kernel - CVE-2026-43086
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in ip_vs_add_service error handling when processing a crafted IPVS service configuration that causes ip_vs_start_estimator() to fail after a scheduler has been successfully bound. A local user can trigger the vulnerable error path to cause a denial of service.
The issue results in a kernel panic.
How to mitigate CVE-2026-43086
Sources
- https://git.kernel.org/stable/c/4039959315008888dd53c37674d33351817a5166
- https://git.kernel.org/stable/c/730663352c9178f33fcf5929f4a37c1f1ca5a693
- https://git.kernel.org/stable/c/9a91797e61d286805ae10a92cc48959c30800556
- https://git.kernel.org/stable/c/a32dabacee111cea083ddd57a03635672e1bff29
- https://git.kernel.org/stable/c/c2ddbe577e2ebf63f2d8fb15cdc7503af70f3e94