CVE-2026-43101Disclosure(linux / linux_kernel)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() We need to check __in6_dev_get() for possible NULL value, as suggested by Yiming Qian. Also add skb_dst_dev_rcu() instead of skb_dst_dev(), and two missing READ_ONCE(). Note that @dev can't be NULL.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 105-0605-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-43101 in Linux IPv6 IOAM: a NULL deref… not RCE, but it’s still “kernel on fire” energy. This matters because WSL turns Linux bugs into Windows downtime. #Windows #Security #WSL https://windowsforum.com/threads/cve-2026-43101-linux-ipv6-ioam-null-dereference-and-what-windows-teams-must-do.416783/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #VulnerabilityManagement #LinuxKernelSecurity #WslAndContainers https://t.co/SQoPygIhUi

    Post summary

    The post announces CVE‑2026‑43101, a NULL‑dereference bug in Linux IPv6 IOAM that could impact WSL, highlighting its severity but providing no exploitation or patch details.

    0000061
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43101 Linux Kernel IPv6 IOAM NULL Dereference Vulnerability in __ioam6_fill_trace_data() https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43101

    Post summary

    The text announces the discovery of CVE-2026-43101, describing a kernel-level NULL dereference vulnerability in the __ioam6_fill_trace_data() function.

    0000049
    4.0K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more