{"cve":{"cve_id":"CVE-2026-53111","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":null,"epss_percentile":null,"epss_as_of":null,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap\n\nThe bpf_lwt_xmit_push_encap helper needs to access skb_dst(skb)->dev to\ncalculate the needed headroom:\n\n\terr = skb_cow_head(skb,\n\t\t\t   len + LL_RESERVED_SPACE(skb_dst(skb)->dev));\n\nBut skb->_skb_refdst may not be initialized when the skb is set up by\nbpf_prog_test_run_skb function. Executing bpf_lwt_push_ip_encap function\nin this scenario will trigger null pointer dereference, causing a kernel\ncrash as Yinhao reported:\n\n[  105.186365] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[  105.186382] #PF: supervisor read access in kernel mode\n[  105.186388] #PF: error_code(0x0000) - not-present page\n[  105.186393] PGD 121d3d067 P4D 121d3d067 PUD 106c83067 PMD 0\n[  105.186404] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[  105.186412] CPU: 3 PID: 3250 Comm: poc Kdump: loaded Not tainted 6.19.0-rc5 #1\n[  105.186423] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[  105.186427] RIP: 0010:bpf_lwt_push_ip_encap+0x1eb/0x520\n[  105.186443] Code: 0f 84 de 01 00 00 0f b7 4a 04 66 85 c9 0f 85 47 01 00 00 31 c0 5b 5d 41 5c 41 5d 41 5e c3 cc cc cc cc 48 8b 73 58 48 83 e6 fe <48> 8b 36 0f b7 be ec 00 00 00 0f b7 b6 e6 00 00 00 01 fe 83 e6 f0\n[  105.186449] RSP: 0018:ffffbb0e0387bc50 EFLAGS: 00010246\n[  105.186455] RAX: 000000000000004e RBX: ffff94c74e036500 RCX: ffff94c74874da00\n[  105.186460] RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff94c74e036500\n[  105.186463] RBP: 0000000000000001 R08: 0000000000000002 R09: 0000000000000000\n[  105.186467] R10: ffffbb0e0387bd50 R11: 0000000000000000 R12: ffffbb0e0387bc98\n[  105.186471] R13: 0000000000000014 R14: 0000000000000000 R15: 0000000000000002\n[  105.186484] FS:  00007f166aa4d680(0000) GS:ffff94c8b7780000(0000) knlGS:0000000000000000\n[  105.186490] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  105.186494] CR2: 0000000000000000 CR3: 000000015eade001 CR4: 0000000000770ee0\n[  105.186499] PKRU: 55555554\n[  105.186502] Call Trace:\n[  105.186507]  <TASK>\n[  105.186513]  bpf_lwt_xmit_push_encap+0x2b/0x40\n[  105.186522]  bpf_prog_a75eaad51e517912+0x41/0x49\n[  105.186536]  ? kvm_clock_get_cycles+0x18/0x30\n[  105.186547]  ? ktime_get+0x3c/0xa0\n[  105.186554]  bpf_test_run+0x195/0x320\n[  105.186563]  ? bpf_test_run+0x10f/0x320\n[  105.186579]  bpf_prog_test_run_skb+0x2f5/0x4f0\n[  105.186590]  __sys_bpf+0x69c/0xa40\n[  105.186603]  __x64_sys_bpf+0x1e/0x30\n[  105.186611]  do_syscall_64+0x59/0x110\n[  105.186620]  entry_SYSCALL_64_after_hwframe+0x76/0xe0\n[  105.186649] RIP: 0033:0x7f166a97455d\n\nTemporarily add the setting of skb->_skb_refdst before bpf_test_run to resolve the issue.","published_at":"2026-06-24T16:30:44.691000Z","last_modified_at":null,"cvss_v3_score":null,"cvss_v3_vector":null,"cvss_v3_severity":null,"cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":null,"nvd_references":["https://git.kernel.org/stable/c/5c8d1f91fc4898d79f29d79c1a6f7c2b3ee66fb0","https://git.kernel.org/stable/c/c7ad31fb948fdd4905263f4324160682c3fa7bc6","https://git.kernel.org/stable/c/599905c3f10bb83e6e6881d5a7f5cea5df07dc23","https://git.kernel.org/stable/c/5500913516e071dbe23e5a404c861dd2d82c9589","https://git.kernel.org/stable/c/94f95328b9070909b5b875c647b17a11d3d85567","https://git.kernel.org/stable/c/972787479ee73006fddb5e59ab5c8e733810ff42"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-28T17:55:28.590503Z","updated_at":"2026-06-28T23:30:50.753831Z"},"effective_severity":null,"badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":null,"metrics":[]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"52f278774e796a553be0c869dcaaee6f259ca795","version_start_inclusive":true,"version_end":"5c8d1f91fc4898d79f29d79c1a6f7c2b3ee66fb0","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:52f278774e796a553be0c869dcaaee6f259ca795:5c8d1f91fc4898d79f29d79c1a6f7c2b3ee66fb0"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"52f278774e796a553be0c869dcaaee6f259ca795","version_start_inclusive":true,"version_end":"c7ad31fb948fdd4905263f4324160682c3fa7bc6","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:52f278774e796a553be0c869dcaaee6f259ca795:c7ad31fb948fdd4905263f4324160682c3fa7bc6"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"52f278774e796a553be0c869dcaaee6f259ca795","version_start_inclusive":true,"version_end":"599905c3f10bb83e6e6881d5a7f5cea5df07dc23","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:52f278774e796a553be0c869dcaaee6f259ca795:599905c3f10bb83e6e6881d5a7f5cea5df07dc23"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"52f278774e796a553be0c869dcaaee6f259ca795","version_start_inclusive":true,"version_end":"5500913516e071dbe23e5a404c861dd2d82c9589","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:52f278774e796a553be0c869dcaaee6f259ca795:5500913516e071dbe23e5a404c861dd2d82c9589"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"52f278774e796a553be0c869dcaaee6f259ca795","version_start_inclusive":true,"version_end":"94f95328b9070909b5b875c647b17a11d3d85567","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:52f278774e796a553be0c869dcaaee6f259ca795:94f95328b9070909b5b875c647b17a11d3d85567"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"52f278774e796a553be0c869dcaaee6f259ca795","version_start_inclusive":true,"version_end":"972787479ee73006fddb5e59ab5c8e733810ff42","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:52f278774e796a553be0c869dcaaee6f259ca795:972787479ee73006fddb5e59ab5c8e733810ff42"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"5.1","version_start_inclusive":true,"version_end":"5.1","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:5.1:5.1"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"0","version_start_inclusive":true,"version_end":"5.1","version_end_inclusive":false,"cpe23_uri":"cve5:linux:linux:0:5.1"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"6.1.175","version_start_inclusive":true,"version_end":"6.1.*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:6.1.175:6.1.*"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"6.6.141","version_start_inclusive":true,"version_end":"6.6.*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:6.6.141:6.6.*"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"6.12.91","version_start_inclusive":true,"version_end":"6.12.*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:6.12.91:6.12.*"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"6.18.33","version_start_inclusive":true,"version_end":"6.18.*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:6.18.33:6.18.*"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"7.0.10","version_start_inclusive":true,"version_end":"7.0.*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:7.0.10:7.0.*"},{"vendor_slug":"linux","vendor_name":"Linux","product_slug":"linux","product_name":"Linux","version_start":"7.1","version_start_inclusive":true,"version_end":"*","version_end_inclusive":true,"cpe23_uri":"cve5:linux:linux:7.1:*"}],"exploit_refs":[],"news":[],"references":[{"url":"https://git.kernel.org/stable/c/5c8d1f91fc4898d79f29d79c1a6f7c2b3ee66fb0","source_type":"MISC","tags":[]},{"url":"https://git.kernel.org/stable/c/c7ad31fb948fdd4905263f4324160682c3fa7bc6","source_type":"MISC","tags":[]},{"url":"https://git.kernel.org/stable/c/599905c3f10bb83e6e6881d5a7f5cea5df07dc23","source_type":"MISC","tags":[]},{"url":"https://git.kernel.org/stable/c/5500913516e071dbe23e5a404c861dd2d82c9589","source_type":"MISC","tags":[]},{"url":"https://git.kernel.org/stable/c/94f95328b9070909b5b875c647b17a11d3d85567","source_type":"MISC","tags":[]},{"url":"https://git.kernel.org/stable/c/972787479ee73006fddb5e59ab5c8e733810ff42","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2026-06-24T16:30:44.691000Z","label":"CVE published","source":null}]}