CVE-2026-23326
In the Linux kernel, the following vulnerability has been resolved: xsk: Fix fragment node deletion to prevent buffer leak After commit b692bf9a7543 ("xsk: Get rid of xdp_buff_xsk::xskb_list_node"), the list_node field is reused for both the xskb pool list and the buffer free list, this causes a buffer leak as described below. xp_free() checks if a buffer is already on the free list using list_empty(&xskb->list_node). When list_del() is used to remove a node from the xskb pool list, it doesn't reinitialize the node pointers. This means list_empty() will return false even after the node has been removed, causing xp_free() to incorrectly skip adding the buffer to the free list. Fix this by using list_del_init() instead of list_del() in all fragment handling paths, this ensures the list node is reinitialized after removal, allowing the list_empty() to work correctly.
EPSS 0.02% · 4.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| linux | linux_kernel | 6.13, 6.13, 6.13 |
| Linux | Linux | 560c974b7ccd95bb9ff20df77f6654283e45c9c6, fd5614763805d6f386bd07cc53558f88b1b1eb62, b692bf9a7543af7ad11a59d182a3757578f0ba53 |
Exploit Intelligence
- https://git.kernel.org/stable/c/5172adf9efb8298a52f4dcdc3f98d4d9d1e06a6d (circl)
- https://git.kernel.org/stable/c/2a9ea988465ece5b6896b1bdc144170a64e84c35 (circl)
- https://git.kernel.org/stable/c/645c6d8376ad4913cbffe0e0c2cca0c4febbe596 (circl)
- https://git.kernel.org/stable/c/b38cbd4af5034635cff109e08788c63f956f3a69 (circl)
- https://git.kernel.org/stable/c/60abb0ac11dccd6b98fd9182bc5f85b621688861 (circl)
- glcve_test.go (github-poc)
- glcve_test.go (github-poc)
- glcve_test.go (github-poc)
- glcve_test.go (github-poc)
- glcve_test.go (github-poc)
Timeline
- Mar 25, 2026 EPSS Score
- Mar 25, 2026 Coalition ESS Score
- Mar 25, 2026 CVE Published
- Mar 29, 2026 Security Advisory
- Apr 23, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
References
- https://git.kernel.org/stable/c/5172adf9efb8298a52f4dcdc3f98d4d9d1e06a6d url
- https://git.kernel.org/stable/c/2a9ea988465ece5b6896b1bdc144170a64e84c35 url
- https://git.kernel.org/stable/c/645c6d8376ad4913cbffe0e0c2cca0c4febbe596 url
- https://git.kernel.org/stable/c/b38cbd4af5034635cff109e08788c63f956f3a69 url
- https://git.kernel.org/stable/c/60abb0ac11dccd6b98fd9182bc5f85b621688861 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-23326 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261532-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-202621230-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261463-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261574-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261527-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-202621114-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261531-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261583-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261505-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-202621221-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-202621120-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-202621123-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261573-1 advisory
- https://www.suse.com/support/update/announcement/2026/suse-su-20261578-1 advisory
…and 20 more