CVE-2026-22998 | Linux Kernel up to 6.12.66/6.18.6/6.19-rc5 nvmet_tcp_handle_h2c_data_pdu null pointer dereference (EUVD-2026-4629 / Nessus ID 296541)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.66/6.18.6/6.19-rc5. This issue affects the function nvmet_tcp_handle_h2c_data_pdu. Performing a manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-22998. The attack must originate from the local network. There is no exploit available.
It is advisable to upgrade the affected component.