---
cve: "CVE-2026-45846"
severity: "LOW"
cvss: 3.1
epss: "13%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-05-27 11:16:24"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T02:12:21+02:00"
---

# CVE-2026-45846

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()

bareudp_fill_metadata_dst() passes bareudp->sock to
udp_tunnel6_dst_lookup() in the IPv6 path without a NULL check.
The socket is only created in bareudp_open() and NULLed in
bareudp_stop(), so calling this function while the device is down
triggers a NULL dereference via sock->sk.

 BUG: kernel NULL pointer dereference, address: 0000000000000018
 RIP: 0010:udp_tunnel6_dst_lookup (net/ipv6/ip6_udp_tunnel.c:160)
 Call Trace:
  
  bareudp_fill_metadata_dst (drivers/net/bareudp.c:532)
  do_execute_actions (net/openvswitch/actions.c:901)
  ovs_execute_actions (net/openvswitch/actions.c:1589)
  ovs_packet_cmd_execute (net/openvswitch/datapath.c:700)
  genl_family_rcv_msg_doit (net/netlink/genetlink.c:1114)
  genl_rcv_msg (net/netlink/genetlink.c:1209)
  netlink_rcv_skb (net/netlink/af_netlink.c:2550)
  

Add a NULL check returning -ESHUTDOWN, consistent with the xmit paths
in the same driver.

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.258
- Kernel ≥ 5.15.209
- Kernel ≥ 6.1.175
- Kernel ≥ 6.6.141
- Kernel ≥ 6.12.91
- Kernel ≥ 6.18.33
- Kernel ≥ 7.0.10

## Referenzen

- <https://git.kernel.org/stable/c/31e010a106ff6cd8ccac4bfee547fd3fa1015574>
- <https://git.kernel.org/stable/c/55193df8d6d33318435f19572bf5ea47a22eee28>
- <https://git.kernel.org/stable/c/51eef9c072aa3405a6823a96ae666d38a3b48750>
- <https://git.kernel.org/stable/c/a0f4e4e8e0f5e24ddd83e3d1221732621cf34636>
- <https://git.kernel.org/stable/c/35a115a204be08f97450b0389413e218268ef4a2>
- <https://git.kernel.org/stable/c/74a02921c48fcd35a7881956c9e5c52b86595f5d>
- <https://git.kernel.org/stable/c/638905520fc4fae6a80991563f264131545ba3df>
- <https://git.kernel.org/stable/c/aa6c6d9ee064aabfede4402fd1283424e649ca19>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-45846) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
