In the Linux kernel, the following vulnerability has been resolved: net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null Fixes a NULL pointer derefence bug triggered …
Medium CVSS 5.5
Summary
In the Linux kernel, the following vulnerability has been resolved: net: tap: NULL pointer derefence in dev_parse_header_protocol when skb->dev is null Fixes a NULL pointer derefence bug triggered from tap driver. When tap_get_user calls virtio_net_hdr_to_skb the skb->dev is null (in tap.c skb->dev is set after the call to virtio_net_hdr_to_skb) virtio_net_hdr_to_skb calls dev_parse_header_protocol which needs skb->dev field to be valid. The line that trigers the bug is in dev_parse_header_p…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/447ba770cfe798925f4923548b367fd49f0ee5f0
- https://git.kernel.org/stable/c/4f61f133f354853bc394ec7d6028adb9b02dd701 Patch
- https://git.kernel.org/stable/c/8f90163f9e013c8fc791aab338aab44a46044cfc
- https://git.kernel.org/stable/c/dd29648fcf69339713f2d25f7014ae905dcdfc18 Patch
- http://www.openwall.com/lists/oss-security/2026/08/12/20
Timeline
- nvd_ingest NVD