NULL pointer dereference in Linux kernel - CVE-2026-64542
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in accept_untracked_na() when handling IPv6 neighbor advertisement packets. A local user can trigger concurrent network namespace activity to cause a denial of service.
It is reachable by an unprivileged user via a network namespace.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64542
linux (Debian package) - update to 6.12.100-1