Kernel Null Pointer Dereference in Linux Kernel Affects Networking Functionality
CVE-2026-64545

7.5HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64545?

A vulnerability exists in the Linux kernel's handling of network devices that can lead to a null pointer dereference due to improper checks in the xdp_master_redirect() function. When the network device lacks an upper master, the function attempts to dereference a NULL pointer, triggering a kernel panic and halting the system. This issue stems from legacy code that did not adequately safeguard against NULL master pointers, potentially leaving the system vulnerable to crashes during network operations.

Affected Version(s)

Linux 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7

Linux 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7

Linux 879af96ffd72706c6e3278ea6b45b0b0e37ec5d7 < 3876318ea54e83eb70982b8280a3c5e4e32269bf

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.