CVE-2026-23011Buffer Underflow in Linux

CWE-124Buffer Underflow13 documents7 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 25
Latest updateApr 17

Description

In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to commit db5b4e39c4e6 ("ip6_gre: make ip6gre_header() robust") Over the years, syzbot found many ways to crash the kernel in ipgre_header() [1]. This involves team or bonding drivers ability to dynamically change their dev->needed_headroom and/or dev->hard_header_len In this particular crash mld_newpack() allocated an skb with a too small reserve/headroom, and by the time mld

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages13 packages

Linuxlinux/linux_kernel3.10.05.10.249+5
NVDlinux/linux_kernel3.10.15.10.249+7
Debianlinux/linux_kernel< 5.10.249-1+3

Patches

🔴Vulnerability Details

3
OSV
ipv4: ip_gre: make ipgre_header() robust2026-01-25
GHSA
GHSA-5ww3-m3hh-c9fg: In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to commit db5b4e39c4e6 ("ip6_gre2026-01-25
OSV
CVE-2026-23011: In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to commit db5b4e39c4e6 ("ip6_gre:2026-01-25

📋Vendor Advisories

8
Ubuntu
Linux kernel (HWE) vulnerabilities2026-04-17
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2026-04-17
Ubuntu
Linux kernel (FIPS) vulnerabilities2026-04-17
Ubuntu
Linux kernel (Real-time) vulnerabilities2026-04-17
Ubuntu
Linux kernel vulnerabilities2026-04-16

🕵️Threat Intelligence

1
Wiz
CVE-2026-23011 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23011 — Buffer Underflow in Linux | cvebase