NULL pointer dereference in Linux kernel - CVE-2026-98098
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in tipc_named_node_up() when processing node state publications after the local publication limit is reached. A local user can bind a large number of local-scope service addresses to sockets to cause a denial of service.
Subscribers to node or link up/down events may stop receiving notifications.