CVE-2026-22988
HIGHLinux Kernel 6.1.160, 6.6.120, 6.12.64-65, 6.18.4-5 - Memory Corruption via ARP Header
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not change skb->head arp_create() is the only dev_hard_header() caller making assumption about skb->head being unchanged. A recent commit broke this assumption. Initialize @arp pointer after dev_hard_header() call.
References (7)
Core 7
Core References
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
6.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (19)
linux/Kernel
6.1.160 - 6.1.161linux
linux/Kernel
6.12.64 - 6.12.66linux
linux/Kernel
6.18.4 - 6.18.6linux
linux/Kernel
6.6.120 - 6.6.121linux
Linux/Linux
1717357007db150c2d703f13f5695460e960f26c - 029935507d0af6553c45380fbf6feecf756fd226
Linux/Linux
17e7386234f740f3e7d5e58a47b5847ea34c3bc2 - e432dbff342b95fe44645f9a90fcf333c80f4b5e
Linux/Linux
41a1a3140aff295dee8063906f70a514548105e8 - 393525dee5c39acff8d6705275d7fcaabcfb7f0a
Linux/Linux
5fe210533e3459197eabfdbf97327dacbdc04d60 - dd6ccec088adff4bdf33e2b2dd102df20a7128fa
Linux/Linux
6.1.160 - 6.1.161
Linux/Linux
6.12.64 - 6.12.66
... and 9 more
Published
Jan 23, 2026
Tracked Since
Feb 18, 2026