In the Linux kernel, the following vulnerability has been resolved:
arp: do not assume devhardheader() does not change skb->head
arpcreate() is the only devhard_header() caller making assumption about skb->head being unchanged.
A recent commit broke this assumption.
Initialize @arp pointer after devhardheader() call.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22988.json"
}