Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-23398 — Proof-of-concept exploit for a Linux kernel NULL pointer dereference in icmp_tag_validation(), enabling remote denial-of-service via crafted ICMP packets. | Kitploit
Tools/GitHubGitHub/johanneslks/cve-2026-23398
Vulnerability AnalysisExploitationPenetration TestingLearning & Education
GitHubjohanneslks/cve-2026-23398

CVE-2026-23398

Proof-of-concept exploit for a Linux kernel NULL pointer dereference in icmp_tag_validation(), enabling remote denial-of-service via crafted ICMP packets.

View Repository
1186 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-23398

Linux Kernel icmp_tag_validation() NULL Pointer Dereference (Remote DoS)

Description

icmp_tag_validation() in net/ipv4/icmp.c dereferences inet_protos[proto] without a NULL check. A remote attacker can send a single crafted ICMP Fragmentation Needed packet with an unregistered inner protocol number to crash the kernel in softirq context.

Affected: Linux kernel before commits 614aefe56af8 (mainline) / d938dd5a0ad7 (stable 6.12)

Usage

sudo python3 poc.py --target <TARGET_IP>                     # single packet, proto 253
sudo python3 poc.py --target <TARGET_IP> --proto 252         # alternate unregistered proto
sudo python3 poc.py --target <TARGET_IP> --count 5           # repeat

Requirements

  • Layer 3 adjacency to target (spoofed source IP supported)
  • Target: net.ipv4.ip_no_pmtu_disc = 3 (non-default; required for icmp_tag_validation() to be reached)
  • Attacker: root, Python 3, Scapy

References

  • https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=d938dd5a0ad780c891ea3bc94cae7405f11e618a
  • https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=614aefe56af8

Legal Notice

This project is released under the GNU GPLv3.

It is provided for defensive security research, education, and authorized testing. Do not use this code against systems or services without explicit permission from the owner.

Unauthorized use may violate applicable law. The authors do not grant permission to test third-party systems and are not responsible for misuse.

See the LICENSE file for warranty and liability terms.

Download Tool