NULL pointer dereference in Linux kernel - CVE-2026-80846
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the handle_esp function when processing queued ESP-in-TCP data after its ingress device has been removed. A remote attacker can send ESP-in-TCP records to cause a denial of service.
The condition can occur during veth or network namespace teardown.
Affected software
How to mitigate CVE-2026-80846
External References
- https://git.kernel.org/stable/c/239d0f71af09dc2029fd4d730cb24b8c83aaa43a
- https://git.kernel.org/stable/c/2dd1609cadff46c4b20ce53b91ab9cce1380456a
- https://git.kernel.org/stable/c/328e40aa774b446969c69b654c52a051a95af8a1
- https://git.kernel.org/stable/c/6af5cdb03819a5ce6e945992635c6c5e91045367
- https://git.kernel.org/stable/c/7911e0236616487b89db6bd3ba3f408abd10eb23
- https://git.kernel.org/stable/c/943d95233b8b4a88994e244fcf466f8c403d63f1
- https://git.kernel.org/stable/c/c296d25efbc840be24de83f56d43bc47e714ace9
- https://git.kernel.org/stable/c/e1d7c5ac1c246ce5775f604515de0a59fbf2116e
- https://git.kernel.org/stable/c/f00235f9d12301183d61f75fbe4105506f3e5140