CVE-2026-23003Use of Uninitialized Resource in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 25
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did not take care of VLAN encapsulations as spotted by syzbot [1]. Use skb_vlan_inet_prepare() instead of pskb_inet_may_pull(). [1] BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages13 packages

Linuxlinux/linux_kernel5.11.05.15.199+5
NVDlinux/linux_kernel5.10.2105.10.249+8
Debianlinux/linux_kernel< 5.10.249-1+3
CVEListV5linux/linuxa9bc32879a08f23cdb80a48c738017e39aea1080f9c5c5b791d3850570796f9e067629474e613796+8
debiandebian/linux< linux 6.1.162-1 (bookworm)

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f9vv-4vcq-qjp3: In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did not2026-01-25
OSV
ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()2026-01-25
OSV
CVE-2026-23003: In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did not t2026-01-25

📋Vendor Advisories

8
Ubuntu
Linux kernel (HWE) vulnerabilities2026-04-17
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2026-04-17
Ubuntu
Linux kernel (FIPS) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel vulnerabilities2026-04-16

🕵️Threat Intelligence

1
Wiz
CVE-2026-23003 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23003 — Use of Uninitialized Resource in Linux | cvebase