NULL pointer dereference in Linux kernel - CVE-2026-89477

 

NULL pointer dereference in Linux kernel - CVE-2026-89477

Published: September 12, 2026


Vulnerability identifier: #VU149327
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89477
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a null pointer dereference in SCTP stream reconfiguration request handling when processing specially crafted SCTP RECONF chunks. A remote attacker can send a specially crafted SCTP RECONF packet to cause a denial of service.

A RECONF chunk containing incoming SSN reset, outgoing SSN reset, and response parameters, or two RECONF chunks in one packet, can trigger the issue.


Affected software

Linux kernel

How to mitigate CVE-2026-89477

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins