CVE-2026-23381Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never initialized because inet6_init() exits before ndisc_init() is called which initializes it. Then, if neigh_suppress is enabled and an ICMPv6 Neighbor Discovery packet reaches the bridge, br_do_suppress_nd() will dereference ipv6_stub->nd_tbl which is NULL, passing it to neigh_lookup(). This causes a kernel NULL pointer dereference. BUG: kernel NULL pointer dereference, address: 0000000000000268 Oops: 0000 [#1] PREEMPT SMP NOPTI [...] RIP: 0010:neigh_lookup+0x16/0xe0 [...] Call Trace: <IRQ> ? neigh_lookup+0x16/0xe0 br_do_suppress_nd+0x160/0x290 [bridge] br_handle_frame_finish+0x500/0x620 [bridge] br_handle_frame+0x353/0x440 [bridge] __netif_receive_skb_core.constprop.0+0x298/0x1110 __netif_receive_skb_one_core+0x3d/0xa0 process_backlog+0xa0/0x140 __napi_poll+0x2c/0x170 net_rx_action+0x2c4/0x3a0 handle_softirqs+0xd0/0x270 do_softirq+0x3f/0x60 Fix this by replacing IS_ENABLED(IPV6) call with ipv6_mod_enabled() in the callers. This is in essence disabling NS/NA suppression when IPv6 is disabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Patch: 1 classified signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 103-2503-2603-27
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-261
Disclosure1
2026-03-271
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23381 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23381 #CVE-2026-23381 #CVE   #CyberSecurity #InfoSec https://t.co/prDW6bLuXN

    Post summary

    The tweet merely announces the existence of CVE‑2026‑23381 with minimal details and no additional technical, exploit, or mitigation information.

    0000028
    123 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🛡️ Another day, another “disabled IPv6” surprise: even with v6 off, bridge neighbor suppression can faceplant the kernel. Proof that networking bugs never truly sleep. #WindowsForum https://windowsforum.com/threads/cve-2026-23381-linux-bridge-crash-when-ipv6-is-disabled.407434/ #LinuxKernel #Cve202623381 #Ipv6Disabled #BridgeNetworking https://t.co/SiXWGzh5Os

    Post summary

    The post reports a newly identified Linux kernel crash vulnerability (CVE‑2026‑23381) related to bridge neighbor suppression when IPv6 is disabled; it provides technical details but no exploit, patch, or evidence of active exploitation.

    0000034
    1.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23381 In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disab… https://www.cve.org/CVERecord?id=CVE-2026-23381

    Post summary

    The statement announces that CVE‑2026‑23381, a null dereference bug in the Linux kernel bridge code, has been fixed, but it provides no PoC, exploit, or detailed patching instructions.

    0000072
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel4.15--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more