NULL pointer dereference in Linux kernel - CVE-2026-45845
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in taprio class dump handling when deleting a TAPRIO child qdisc and requesting a class dump. A local user can delete an explicit child qdisc and trigger a class dump to cause a denial of service.
Exploitation is reachable in a network namespace with CAP_NET_ADMIN, and on systems with unprivileged user namespaces enabled, user interaction is not required.
How to mitigate CVE-2026-45845
Sources
- https://git.kernel.org/stable/c/3d07ca5c0fae311226f737963984bd94bb159a87
- https://git.kernel.org/stable/c/48b26d48e76221dc90b02bf5428bab53643461ca
- https://git.kernel.org/stable/c/8f1ff8866cb9f655e5faea6994eb902960be8e04
- https://git.kernel.org/stable/c/d02e2fbf60de46678e2ea698a6a904fd21e1cc31
- https://git.kernel.org/stable/c/ec2501e361b08b50bcb1e7b3253fc861abbda28d