CVE-2026-97601

Source
https://cve.org/CVERecord?id=CVE-2026-97601
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97601.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97601
Downstream
Published
2026-09-25T10:22:14Z
Modified
2026-09-26T03:48:36Z
Summary
ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink
Details

In the Linux kernel, the following vulnerability has been resolved:

ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink

TUNSETLINK allows a TUN device to change its link-layer type to ARPHRD_IEEE802154 without initializing ieee802154_ptr. lowpan_newlink() checks only the device type before dereferencing the pointer, so an RTM_NEWLINK request can trigger a NULL pointer dereference.

Reject devices without ieee802154_ptr along with devices of the wrong type.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97601.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
51e0e5d8124ece158927a4c2288c0929d3b53aa3
Fixed
1c7710af7ad9532b534f1c134c11b04dbe4e0e0f
Fixed
98ce5a42cde780ee0e40378607d4428c8fc12ec1
Fixed
8528da2333ce05cf627f93425f9d05efb08b3146
Fixed
bf79662bc85e820ac3b846e2f347da29fbf6ac95

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97601.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97601.json"