CVE-2026-23398: icmp: fix NULL pointer dereference in icmp_tag_validation()
Published Mar 26, 2026
·Updated
icmp: fix NULL pointer dereference in icmptagvalidation()
Affected Software
17 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.126.1-1
Linux Linux kernel>=3.14.1<5.10.253
Linux Linux kernel>=5.11<5.15.203
Linux Linux kernel>=5.16<6.1.167
Linux Linux kernel>=6.2<6.6.130
Linux Linux kernel>=6.7<6.12.78
Linux Linux kernel>=6.13<6.18.20
Linux Linux kernel>=6.19<6.19.10
Linux Linux kernel=3.14
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
Event History
Mar 26, 2026
CVE Published
via MITRE·10:22 AM
Data Sourced
via MITRE·10:22 AM
Description
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 27, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:03 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-23398?
CVE-2026-23398 has a high severity rating due to the potential for a NULL pointer dereference that can lead to system crashes.
2
How do I fix CVE-2026-23398?
The fix for CVE-2026-23398 involves updating your Linux kernel to the latest stable version where the vulnerability has been patched.
3
Which versions of the Linux kernel are affected by CVE-2026-23398?
CVE-2026-23398 affects certain versions of the Linux kernel prior to the patch being applied.
4
What are the potential impacts of CVE-2026-23398?
Exploitation of CVE-2026-23398 could lead to denial of service due to NULL pointer dereference in the icmp_tag_validation() function.
5
Is CVE-2026-23398 related to network security?
Yes, CVE-2026-23398 is related to network security as it affects the ICMP protocol handling in the Linux kernel.