PT-2026-52005 · Linux+2 · Linux Kernel+2

CVE-2026-53111

·

Published

2026-03-04

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 6.19.0-rc5
Description A null pointer dereference issue exists in the bpf lwt xmit push encap helper. The issue occurs because the skb-> skb refdst variable may not be initialized when the socket buffer (skb) is set up by the bpf prog test run skb() function. When the bpf lwt push ip encap() function is executed in this state, it attempts to access skb dst(skb)->dev to calculate the required headroom, leading to a kernel crash.
Recommendations As a temporary workaround, add the setting of the skb-> skb refdst variable before calling bpf test run().

Exploit

Fix

NULL Pointer Dereference

Improper Initialization

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13998
CVE-2026-53111
ECHO-1CC6-98CC-276E
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8618-1
USN-8619-1
USN-8663-1
USN-8664-1
USN-8665-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu