CVE-2026-80646

Source
https://cve.org/CVERecord?id=CVE-2026-80646
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80646.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80646
Downstream
BELL (1)
DEBIAN (1)
openSUSE (1)
SUSE (4)
UBUNTU (1)
Related
Published
2026-08-28T06:48:56Z
Modified
2026-10-08T02:52:02Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
ipv6: guard against possible NULL deref in __in6_dev_stats_get()
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv6: guard against possible NULL deref in __in6_dev_stats_get()

dev_get_by_index_rcu() could return NULL if the original physical device is unregistered.

Found by Sashiko.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80646.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f
Fixed
a23f2c68c6635e41404f189f8f7ae910738cebdb
Fixed
e14db43677946bf2095febd294bb3c13ab375ab7
Fixed
1a4adfbeb47a212a64539137411f1ca168474d33
Fixed
1e3db30a88815bae6e9d5db6f64ac735e615a07e
Fixed
952426a83ca75cea25c09d58944abafaa3ebd242
Fixed
0db1949084e85a72d174a7dea3259b94fe5a9305
Fixed
fc920c0659cdea5afd8721c1155a51564859e075
Fixed
507541c2a8eeb76c02bd2511958f73a8cfa3e1bc
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.19.291
Fixed
4.20
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a24963500a4ec921ce9c2597e0a584e44513afae

Affected versions

v4.*
v4.19.291
v4.19.292
v4.19.293
v4.19.294
v4.19.295
v4.19.296
v4.19.297
v4.19.298
v4.19.299
v4.19.300
v4.19.301
v4.19.302
v4.19.303
v4.19.304
v4.19.305
v4.19.306
v4.19.307
v4.19.308
v4.19.309
v4.19.310
v4.19.311
v4.19.312
v4.19.313
v4.19.314
v4.19.315
v4.19.316
v4.19.317
v4.19.318
v4.19.319
v4.19.320
v4.19.321
v4.19.322
v4.19.323
v4.19.324
v4.19.325

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80646.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80646.json"