Answer in brief
CVE-2026-80646 records a Unknown severity vulnerability in ipv6: guard against possible NULL deref in __in6_dev_stats_get(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f <a23f2c68c6635e41404f189f8f7ae910738cebdb || >=e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f <e14db43677946bf2095febd294bb3c13ab375ab7 || >=e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f <1a4adfbeb47a212a64539137411f1ca168474d33 || >=e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f <1e3db30a88815bae6e9d5db6f64ac735e615a07e || >=e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f <952426a83ca75cea25c09d58944abafaa3ebd242 || >=e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f <0db1949084e85a72d174a7dea3259b94fe5a9305 || >=e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f <fc920c0659cdea5afd8721c1155a51564859e075 || >=e1ae5c2ea4783b1fd87be250f9fcc9d9e1a6ba3f <507541c2a8eeb76c02bd2511958f73a8cfa3e1bc || a24963500a4ec921ce9c2597e0a584e44513afae || >=4.19.291 <4.20 | a23f2c68c6635e41404f189f8f7ae910738cebdb, e14db43677946bf2095febd294bb3c13ab375ab7, 1a4adfbeb47a212a64539137411f1ca168474d33, 1e3db30a88815bae6e9d5db6f64ac735e615a07e, 952426a83ca75cea25c09d58944abafaa3ebd242, 0db1949084e85a72d174a7dea3259b94fe5a9305, fc920c0659cdea5afd8721c1155a51564859e075, 507541c2a8eeb76c02bd2511958f73a8cfa3e1bc, 4.20 |
| Linux/Linuxgeneric | 5.2 | Not reported |
Published upstream
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 28, 2026
In the Linux kernel, the following vulnerability has been resolved: ipv6: guard against possible NULL deref in __in6_dev_stats_get() dev_get_by_index_rcu() could return NULL if the original physical device is unregistered. Found by Sashiko.
Quoted source text, attributed separately from HOL analysis.