SB2026040670 - Memory corruption in Linux kernel net
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory corruption (CVE-ID: CVE-2026-23459)
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to memory corruption in iptunnel_xmit_stats() when updating tunnel transmit statistics for vxlan or geneve traffic. A local attacker can trigger the vulnerable code path to cause a denial of service.
On 32-bit kernels, overwriting the syncp sequence could lead to corruption or system freezes.
Remediation
Install update from vendor's website.