PatchSiren cyber security CVE debrief
CVE-2026-45846 Linux CVE debrief
A NULL pointer dereference vulnerability was found in the Linux kernel's bareudp_fill_metadata_dst() function. This function is called while the device is down, triggering a NULL dereference via sock->sk. The vulnerability has been resolved by adding a NULL check returning -ESHUTDOWN. The affected component is the Linux kernel, specifically the bareudp module. This vulnerability is classified as a NULL pointer dereference, which can cause a system crash or potentially allow an attacker to execute arbitrary code. Linux kernel maintainers and users should apply patches to prevent this vulnerability. The vulnerability was reported in the Linux kernel and resolved by adding a NULL.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-06-25
Who should care
Linux kernel maintainers, Linux distribution maintainers, and users of Linux kernel versions affected by this vulnerability. These individuals should apply patches to prevent this vulnerability and assess the exposure of their Linux kernel deployments. They should also monitor Linux kernel updates for potential future vulnerabilities and verify Linux kernel versions to ensure patched versions are used.
Why it matters
This vulnerability in the Linux kernel can cause a NULL pointer dereference when the bareudp_fill_metadata_dst() function is called while the device is down. Linux kernel maintainers and users should apply patches to prevent this vulnerability.
- Verify Linux kernel versions and apply patches to prevent NULL pointer dereferences
- Monitor Linux kernel updates for potential future vulnerabilities
- Assess exposure of Linux kernel deployments to this vulnerability
Technical summary
The Linux kernel's bareudp_fill_metadata_dst() function did not check for NULL before calling udp_tunnel6_dst_lookup(). This led to a NULL pointer dereference when the device was down. A fix has been applied to return -ESHUTDOWN in such cases. The affected product is the Linux kernel, specifically the bareudp module. The vulnerability is a NULL pointer dereference, which can cause a system crash or potentially allow an attacker to execute arbitrary code. The fix involves adding a NULL check to prevent the NULL pointer dereference.
Defensive priority
Medium priority for Linux kernel maintainers and users to apply patches
Recommended defensive actions
- Apply patches provided by Linux kernel maintainers
- Review and update Linux kernel versions to ensure patched versions are used
- Monitor Linux kernel updates for potential future vulnerabilities
- Verify Linux kernel versions and apply patches to prevent NULL pointer dereferences
- Assess exposure of Linux kernel deployments to this vulnerability
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability was reported in the Linux kernel and resolved by adding a NULL check. The CVE record and NVD entry provide details on the vulnerability. The Linux kernel maintainers and users should verify the affected scope and apply patches to prevent this vulnerability. The vulnerability is a NULL pointer dereference, which can cause a system crash or potentially allow an attacker to execute arbitrary code.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45846 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45846
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45846 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45846
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/31e010a106ff6cd8ccac4bfee547fd3fa1015574
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/35a115a204be08f97450b0389413e218268ef4a2
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/51eef9c072aa3405a6823a96ae666d38a3b48750
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/55193df8d6d33318435f19572bf5ea47a22eee28
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/638905520fc4fae6a80991563f264131545ba3df
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/74a02921c48fcd35a7881956c9e5c52b86595f5d
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a0f4e4e8e0f5e24ddd83e3d1221732621cf34636
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/aa6c6d9ee064aabfede4402fd1283424e649ca19
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.