NULL pointer dereference in Linux kernel - CVE-2026-53069
Published: June 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in xdp_master_redirect() when processing XDP redirect operations for a master device that is not up. A local user can trigger the vulnerable code path to cause a denial of service.
The issue can be reached through the bonding round-robin transmit slave selection path when XDP redirection is enabled system-wide and the bond device was never opened.
How to mitigate CVE-2026-53069
Sources
- https://git.kernel.org/stable/c/183128da0406b1c10e6f60b7b9fe70788b9c8c1d
- https://git.kernel.org/stable/c/1921f91298d1388a0bb9db8f83800c998b649cb3
- https://git.kernel.org/stable/c/3128b294b426533c8d9162187446d93a8a160359
- https://git.kernel.org/stable/c/7bad93e99737e4a5c0c14ac50c05152cf4e28022
- https://git.kernel.org/stable/c/866d3d9b87751b1944168fd82615505e0c0fd6cf
- https://git.kernel.org/stable/c/acbf45bd584d924b320bee2a7fe2a26f64904d95
- https://git.kernel.org/stable/c/ea690b3b6e58ae00979af8195b4cc24df466b65e