NULL pointer dereference in Linux kernel - CVE-2026-45842
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the SLIP/PPP VJ receive handling code when processing inbound VJ-compressed or VJ-uncompressed frames after installing a malformed VJ state with zero receive slots. A local user can configure PPP compression state through /dev/ppp and trigger processing of a frame selecting slot 0 to cause a denial of service.
The issue is reachable through PPPIOCSMAXCID from an unprivileged user namespace.
How to mitigate CVE-2026-45842
Sources
- https://git.kernel.org/stable/c/7b0d9e878ec2b21d99ae8051b3dda59cdb66c152
- https://git.kernel.org/stable/c/9e1ff0eead073c4f46d874ad2526b7dda5465faf
- https://git.kernel.org/stable/c/c6980e8b1a86288167f34966fa5219031999b6f1
- https://git.kernel.org/stable/c/de42f86e2cf5028a97e74c25869d1a962b13c301
- https://git.kernel.org/stable/c/e76607442d5b73e1ba6768f501ef815bb58c2c0e