Null Dereference Vulnerability in Linux Kernel Affecting Network Functionality
CVE-2026-64542

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64542?

A vulnerability exists in the Linux kernel's handling of IPv6 Neighbor Discovery. The function accept_untracked_na() incorrectly dereferences a pointer without performing a NULL check. This can lead to a system crash when the pointer is cleared by a concurrent process, allowing unprivileged users to exploit the vulnerability via a network namespace. A fix has been implemented to use a validated pointer instead of refetching it, enhancing the stability and security of IPv6 network operations.

Affected Version(s)

Linux aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 < 62c719203cb521b64fab74da94a81bdde5c18808

Linux aaa5f515b16b6b3e137779ffb4c9558bb58c1e75

Linux aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 < 63d1c23764de2309cedbb779c75188d257a09d9b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.