Out-of-bounds write in Linux kernel - CVE-2026-23359

 

Out-of-bounds write in Linux kernel - CVE-2026-23359

Published: March 25, 2026


Vulnerability identifier: #VU124489
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23359
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code or cause a denial of service.

The vulnerability exists due to a boundary error in the BPF devmap component when handling upper device interface indices. A local user can trigger a stack-out-of-bounds write by creating more than MAX_NEST_DEV (8) macvlans on a device with an XDP program attached using BPF_F_BROADCAST | BPF_F_EXCLUDE_INGRESS and sending a packet to the device, leading to memory corruption.

To exploit this vulnerability, the attacker must have the ability to create macvlan devices and attach XDP programs, which requires local access and privileges to perform network configuration.


Affected software

Linux kernel
Debian Linux
Ubuntu
openEuler
linux (Ubuntu package)
linux-aws (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-nvidia-tegra-5.15 (Ubuntu package)
linux-intel-iot-realtime (Ubuntu package)
linux-intel-iotg (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-5.15 (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux (Debian package)
python3-perf
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
kernel-source
kernel-tools
kernel-tools-debuginfo
bpftool-debuginfo
bpftool
kernel
kernel-tools-devel
perf
perf-debuginfo
python3-perf-debuginfo
kernel-extra-modules
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-raspi (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-gcp-fips (Ubuntu package)

How to mitigate CVE-2026-23359

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 5.15.0.184.155, 5.15.0-184.194, 5.15.0-184.194~20.04.1, 5.15.0.186.166, 5.15.0-186.196, 5.15.0-186.196~20.04.1, 5.15.0.1075.78, 5.15.0-1075.79, 5.15.0.1095.94, 5.15.0-1095.103, 5.15.0.1104.100, 5.15.0-1104.109, 5.15.0.1108.107, 5.15.0-1108.114, 5.15.0.1111.115, 5.15.0-1111.120+fips1, 5.15.0.1112.102, 5.15.0.1112.109, 5.15.0-1112.122, 5.15.0-1112.122+fips1, 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2
linux-aws (Ubuntu package) - addressed in versions 5.15.0.186.109, 5.15.0-186.196+fips1, 5.15.0.1106.103, 5.15.0-1106.110, 5.15.0.1107.107, 5.15.0-1107.108, 5.15.0.1112.108, 5.15.0.1112.115, 5.15.0-1112.119, 5.15.0-1112.119+fips1, 5.15.0-1112.119~20.04.1, 6.8.0-1061.64+1
linux-nvidia-tegra (Ubuntu package) - addressed in versions 5.15.0-1053.53, 5.15.0.1053.55, 5.15.0.1064.64, 5.15.0-1064.66
linux-nvidia-tegra-5.15 (Ubuntu package) - update to 5.15.0-1064.66~20.04.1
linux-intel-iot-realtime (Ubuntu package) - addressed in versions 5.15.0-1104.106, 5.15.0.1104.108, 5.15.0-1107.113~20.04.1
linux-intel-iotg (Ubuntu package) - addressed in versions 5.15.0.1107.106, 5.15.0-1107.113
linux-azure (Ubuntu package) - addressed in versions 5.15.0.1109.105, 5.15.0-1109.115, 5.15.0.1117.115, 5.15.0-1117.126, 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-azure-5.15 (Ubuntu package) - addressed in versions 5.15.0-1109.115~20.04.1, 5.15.0-1117.126~20.04.1, 5.15.0-1117.126~20.04.2
linux-gcp-5.15 (Ubuntu package) - update to 5.15.0-1112.122~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1117.102, 5.15.0-1117.126+fips1, 6.8.0-1063.71+fips2
linux-azure-fde (Ubuntu package) - addressed in versions 5.15.0-1117.126, 6.8.0-1062.69
linux (Debian package) - addressed in versions 6.1.170-1, 6.12.85-1
python3-perf - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-headers - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-devel - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-debugsource - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-debuginfo - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-source - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-tools - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-tools-debuginfo - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
bpftool-debuginfo - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
bpftool - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-tools-devel - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
perf - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
perf-debuginfo - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
python3-perf-debuginfo - addressed in versions 6.6.0-145.1.12.150, 6.6.0-145.3.29.160
kernel-extra-modules - update to 6.6.0-145.3.29.160
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-raspi (Ubuntu package) - addressed in versions 6.8.0-1061.65, 6.8.0-2050.52
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1

External References

Related Security Bulletins