Security Flaw in Linux Kernel Affecting Network Packet Processing
CVE-2026-80846

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80846?

A vulnerability exists within the Linux kernel's handling of ESP-in-TCP packets, where TCP traffic may be processed even after the original ingress interface has been removed. This occurs during scenarios such as veth or network namespace teardown, potentially leading to null pointer dereferences. To mitigate this issue, the kernel is configured to drop ESP-in-TCP packets when the ingress device cannot be resolved, maintaining system stability and ensuring packets only traverse the intended XFRM routing path.

Affected Version(s)

Linux e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < 239d0f71af09dc2029fd4d730cb24b8c83aaa43a

Linux e27cca96cd68fa2c6814c90f9a1cfd36bb68c593

Linux e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < 6af5cdb03819a5ce6e945992635c6c5e91045367

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.