CVE Database
/

CVE-2026-23459

Back to search

CVE-2026-23459

Published: Apr 3, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

8.2

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats() was assuming tunnels were only using NETDEV_PCPU_STAT_TSTATS. @syncp offset in pcpu_sw_netstats and pcpu_dstats is different. 32bit kernels would either have corruptions or freezes if the syncp sequence was overwritten. This patch also moves pcpu_stat_type closer to dev->{t,d}stats to avoid a potential cache line miss since iptunnel_xmit_stats() needs to read it.

VendorProductVersions

Linux

Linux

affected
be226352e8dc77d3313c096b2d8e7f69bf6980fc - < 0d087d00161f562d5047cc4009bb0c6a19daf9f1
affected
be226352e8dc77d3313c096b2d8e7f69bf6980fc - < 8431c602f551549f082bbfa67f3003f2d8e3e132

Linux

Linux

affected
6.14
unaffected
0 - < 6.14
unaffected
6.19.10 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now