CVE-2026-23001

Source
https://cve.org/CVERecord?id=CVE-2026-23001
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23001.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23001
Downstream
Related
Published
2026-01-25T14:36:15.790Z
Modified
2026-03-23T05:11:34.394171Z
Summary
macvlan: fix possible UAF in macvlan_forward_source()
Details

In the Linux kernel, the following vulnerability has been resolved:

macvlan: fix possible UAF in macvlanforwardsource()

Add RCU protection on (struct macvlansourceentry)->vlan.

Whenever macvlanhashdel_source() is called, we must clear entry->vlan pointer before RCU grace period starts.

This allows macvlanforwardsource() to skip over entries queued for freeing.

Note that macvlandev are already RCU protected, as they are embedded in a standard netdev (netdevpriv(ndev)).

https: //lore.kernel.org/netdev/695fb1e8.050a0220.1c677c.039f.GAE@google.com/T/#u

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23001.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
79cf79abce71eb7dbc40e2f3121048ca5405cb47
Fixed
8133e85b8a3ec9f10d861e0002ec6037256e987e
Fixed
484919832e2db6ce1e8add92c469e5d459a516b5
Fixed
232afc74a6dde0fe1830988e5827921f5ec9bb3f
Fixed
15f6faf36e162532bec5cc05eb3fc622108bf2ed
Fixed
8518712a2ca952d6da2238c6f0a16b4ae5ea3f13
Fixed
6dbead9c7677186f22b7981dd085a0feec1f038e
Fixed
7470a7a63dc162f07c26dbf960e41ee1e248d80e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23001.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.18.0
Fixed
5.10.249
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.199
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.162
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.122
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.67
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23001.json"