CVE-2026-23398 is a NULL pointer dereference in the Linux kernel's icmp_tag_validation() function, introduced in Linux 3.14. The function dereferences the protocol handler returned by rcu_dereference(inet_protos[proto]) without checking whether it is NULL. Because the protocol-handler array is sparse, an unregistered protocol number produces a NULL pointer. When hardened Path MTU Discovery mode is enabled, receiving an ICMP Fragmentation Needed error whose quoted inner IP header specifies such a protocol number can trigger a kernel panic in softirq context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a reproducible lab and operational proof-of-concept for CVE-2026-23398, a Linux kernel denial-of-service issue in ICMP handling. The core exploit is send_frag_needed.py, a Python/Scapy script that crafts an ICMP Destination Unreachable / Fragmentation Needed packet (type 3, code 4) containing a quoted inner IPv4 header with a rare protocol number (default 253). On vulnerable Linux kernels where net.ipv4.ip_no_pmtu_disc=3 and the packet is processed through the normal IPv4 receive path, this can trigger a NULL dereference in ICMP processing and panic the kernel. Repository structure: the main exploit logic is in send_frag_needed.py; send-payload-to-host.sh is a convenience wrapper that resolves a hostname/IP and sends the packet either through Docker or directly with Python as root. A Dockerfile and docker-compose.yml build a minimal Scapy-based sender container using host networking and NET_RAW/NET_ADMIN capabilities. The scripts/ directory automates lab setup: downloading an Ubuntu cloud image, preparing a QEMU overlay disk, generating cloud-init seed images, starting/stopping VMs in either usernet or TAP mode, waiting for SSH, and optionally installing an older vulnerable Ubuntu mainline kernel (6.12.0-061200) inside the guest. scripts/poc-veth-netns.sh creates a veth pair and network namespace inside the guest so the crafted ICMP traverses a real ingress path, which is important for reliable triggering. The vm/ directory contains cloud-init metadata and network configuration that also persistently set net.ipv4.ip_no_pmtu_disc=3. victim_dump.log contains a captured kernel panic trace demonstrating successful exploitation. Main capability: remote network-triggered denial of service against vulnerable Linux kernels by sending one crafted ICMP packet. It does not provide code execution, persistence, or post-exploitation features. The exploit is more than a simple detector because it actively transmits the malformed packet and includes automation to provision a vulnerable target and reproduce the crash.
This repository is a small, single-purpose Python proof-of-concept exploit for CVE-2026-23398, a Linux kernel NULL pointer dereference in icmp_tag_validation() reachable via crafted ICMP Fragmentation Needed traffic. The repository contains three files: a GPLv3 LICENSE, a README describing the vulnerability, prerequisites, and usage, and one executable code file, poc.py. The exploit logic is entirely in poc.py. It uses Scapy to construct an outer IPv4 packet addressed to the victim, carrying an ICMP Type 3 Code 4 (Destination Unreachable / Fragmentation Needed) message. Inside that ICMP payload, it embeds a forged inner IPv4 header representing an alleged original packet sent by the victim. The embedded inner header sets src to the target IP, dst to a configurable spoofed address (default 1.2.3.4), and proto to an unregistered protocol number (default 253, configurable via --proto). This is intended to force the kernel into the path icmp_rcv() -> icmp_unreach() -> icmp_tag_validation(), where inet_protos[proto] is dereferenced without a NULL check for unregistered protocols. Capabilities: the script can send a single packet or multiple packets (--count), vary the inner protocol number (--proto), choose the spoofed inner destination (--source), and optionally select an interface (--iface). It requires raw socket access, so it must be run as root. The exploit is pre-authentication and remote over IP, but it is not universally reachable: the README and script both state that the target must have net.ipv4.ip_no_pmtu_disc=3 set, which is a non-default configuration and a necessary precondition for the vulnerable path to be exercised. This is a real exploit rather than a detector. Its intended result is denial of service via kernel panic/general protection fault in softirq context on an unpatched vulnerable Linux kernel. There is no post-exploitation payload such as code execution or shell access; the payload is the malformed network packet itself.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A NULL pointer dereference in the Linux kernel's ICMP handling can cause a kernel panic and denial of service when hardened PMTU mode is enabled and a received ICMP error quotes an IP header with an unregistered protocol number. The reference rates it Medium, with a CVSS v3 base score of 5.5, and states that exploits and patches are available.
A vulnerability addressed by the referenced Alma Linux 9.2 security update.
A Linux kernel NULL pointer dereference vulnerability in net/ipv4/icmp.c within icmp_tag_validation() that can trigger a kernel panic when processing certain ICMP Fragmentation Needed messages containing an unregistered inner protocol number under hardened PMTU mode.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.