CVE-2026-23398 | Linux Kernel up to 7.0-rc4 net/ipv4/icmp.c icmp_tag_validation inet_protos[] null pointer dereference (WID-SEC-2026-0879)
A vulnerability was found in Linux Kernel up to 7.0-rc4. It has been classified as critical. This affects the function icmp_tag_validation of the file net/ipv4/icmp.c. This manipulation of the argument inet_protos[] causes null pointer dereference.
This vulnerability is registered as CVE-2026-23398. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.