Improper Access Control in Linux kernel - CVE-2026-23310
Published: March 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access control in the bonding driver when changing the xmit_hash_policy to vlan+srcmac while an XDP program is loaded on a bond interface in 802.3ad or balance-xor mode. A local user can change the xmit_hash_policy to cause an inconsistent state, leading to failure in uninstalling the XDP program and triggering a kernel warning during bond device destruction.
The attacker must have the ability to configure bonding interface settings, which requires local access and privileges to modify network device parameters.
Affected software
Debian Linux
Ubuntu
openEuler
python3-perf-debuginfo
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
kernel-source
kernel-extra-modules
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)
linux (Debian package)
How to mitigate CVE-2026-23310
python3-perf-debuginfo - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
bpftool - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
bpftool-debuginfo - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-debuginfo - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-debugsource - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-devel - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-headers - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-tools - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-tools-debuginfo - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-tools-devel - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
perf - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
perf-debuginfo - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
python3-perf - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-source - addressed in versions 6.6.0-145.0.2.130, 6.6.0-145.0.2.142, 6.6.0-145.0.2.143
kernel-extra-modules - update to 6.6.0-145.0.2.143
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - update to 6.8.0-1061.64+1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1
linux (Debian package) - update to 6.12.85-1
External References
- https://git.kernel.org/stable/c/0ace8027e41f6f094ef6c1aca42d2ed6cd7af54e
- https://git.kernel.org/stable/c/479d589b40b836442bbdadc3fdb37f001bb67f26
- https://git.kernel.org/stable/c/5c262bd0e39320a6d6c8277cb8349ce21c01b8c1
- https://git.kernel.org/stable/c/d36ad7e126c6a0c5f699583309ccc37e3a3263ea
- https://git.kernel.org/stable/c/e85fa809e507b9d8eff4840888b8c727e4e8448c
Related Security Bulletins
- Improper Access Control in Linux kernel net
- openEuler 24.03 LTS SP2 update for kernel
- openEuler 24.03 LTS SP1 update for kernel
- openEuler 24.03 LTS update for kernel
- Debian update for linux
- Ubuntu update for linux
- Ubuntu update for linux-gcp-fips
- Ubuntu update for linux-oracle-6.8
- Ubuntu update for linux-fips
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-azure-fde-6.8
- Ubuntu update for linux-azure-fips
- Ubuntu update for linux-azure-fde
- Ubuntu update for linux-azure
- Ubuntu update for linux-aws
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-ibm