๐Ÿ” CVE Alert

CVE-2026-52998

UNKNOWN 0.0

netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check The nf_osf_ttl() function accessed skb->dev to perform a local interface address lookup without verifying that the device pointer was valid. Additionally, the implementation utilized an in_dev_for_each_ifa_rcu loop to match the packet source address against local interface addresses. It assumed that packets from the same subnet should not see a decrement on the initial TTL. A packet might appear it is from the same subnet but it actually isn't especially in modern environments with containers and virtual switching. Remove the device dereference and interface loop. Replace the logic with a switch statement that evaluates the TTL according to the ttl_check.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < f4de0777e4554a7de19c920accde6319dd530782 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < c996a90f3071cf43683e5423da31aadbe002b8b4 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < edc806f9122961f0d3819f7c69c14cccde31f277 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 5d05de2f0928d81309a815ecc76d1a3ad72cbc16 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 95be653a76793856ff8b2d8bd82c2943c23f5ca8 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 79b90a96688e521771fa6ed3dc7864b76b8df293 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 83fc5dd63455a779ea2dd0f7ffee3c920919d80b 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 < 711987ba281fd806322a7cd244e98e2a81903114
Linux / Linux
2.6.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f4de0777e4554a7de19c920accde6319dd530782 git.kernel.org: https://git.kernel.org/stable/c/c996a90f3071cf43683e5423da31aadbe002b8b4 git.kernel.org: https://git.kernel.org/stable/c/edc806f9122961f0d3819f7c69c14cccde31f277 git.kernel.org: https://git.kernel.org/stable/c/5d05de2f0928d81309a815ecc76d1a3ad72cbc16 git.kernel.org: https://git.kernel.org/stable/c/95be653a76793856ff8b2d8bd82c2943c23f5ca8 git.kernel.org: https://git.kernel.org/stable/c/79b90a96688e521771fa6ed3dc7864b76b8df293 git.kernel.org: https://git.kernel.org/stable/c/83fc5dd63455a779ea2dd0f7ffee3c920919d80b git.kernel.org: https://git.kernel.org/stable/c/711987ba281fd806322a7cd244e98e2a81903114