{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "51e0e5d8124ece158927a4c2288c0929d3b53aa3"
            },
            {
              "fixed": "1c7710af7ad9532b534f1c134c11b04dbe4e0e0f"
            },
            {
              "fixed": "98ce5a42cde780ee0e40378607d4428c8fc12ec1"
            },
            {
              "fixed": "8528da2333ce05cf627f93425f9d05efb08b3146"
            },
            {
              "fixed": "bf79662bc85e820ac3b846e2f347da29fbf6ac95"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.3.0"
            },
            {
              "fixed": "6.12.111"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.53"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97601.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: 6lowpan: fix NULL dereference in lowpan_newlink\n\nTUNSETLINK allows a TUN device to change its link-layer type to\nARPHRD_IEEE802154 without initializing ieee802154_ptr. lowpan_newlink()\nchecks only the device type before dereferencing the pointer, so an\nRTM_NEWLINK request can trigger a NULL pointer dereference.\n\nReject devices without ieee802154_ptr along with devices of the wrong type.",
  "id": "CVE-2026-97601",
  "modified": "2026-09-27T03:30:38.585671615Z",
  "published": "2026-09-25T10:22:14.792Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1c7710af7ad9532b534f1c134c11b04dbe4e0e0f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8528da2333ce05cf627f93425f9d05efb08b3146"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/98ce5a42cde780ee0e40378607d4428c8fc12ec1"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/bf79662bc85e820ac3b846e2f347da29fbf6ac95"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97601.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97601"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink"
}