PT-2026-97973 · Linux · Linux

CVE-2026-93286

·

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: appletalk: fix NULL pointer dereference in aarp send ddp()
aarp send ddp() calls atalk find dev addr(dev) in the LocalTalk fast path without checking for NULL. When the device has no AppleTalk interface configured (dev->atalk ptr == NULL), this leads to a NULL pointer dereference at the at->s net access.
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:aarp send ddp (net/appletalk/aarp.c:552 (discriminator 2)) Call Trace: atalk sendmsg (net/appletalk/ddp.c:1715) sys sendto (net/socket.c:2265 (discriminator 1)) x64 sys sendto (net/socket.c:2272) do syscall 64 (arch/x86/entry/syscall 64.c:94) entry SYSCALL 64 after hwframe (arch/x86/entry/entry 64.S:121)
Add a NULL check consistent with the other callers of atalk find dev addr().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93286

Affected Products

Linux