cbcvebase.
CVE-2026-23209
published 2026-02-14

CVE-2026-23209: In the Linux kernel, the following vulnerability has been resolved: macvlan: fix error recovery in macvlan_common_newlink() valis provided a nice repro to…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.1th percentile
In the Linux kernel, the following vulnerability has been resolved: macvlan: fix error recovery in macvlan_common_newlink() valis provided a nice repro to crash the kernel: ip link add p1 type veth peer p2 ip link set address 00:00:00:00:00:20 dev p1 ip link set up dev p1 ip link set up dev p2 ip link add mv0 link p2 type macvlan mode source ip link add invalid% link p2 type macvlan mode source macaddr add 00:00:00:00:00:20 ping -c1 -I p1 1.2.3.4 He also gave a very detailed analysis: The issue is triggered when a new macvlan link is created with MACVLAN_MODE_SOURCE mode and MACVLAN_MACADDR_ADD (or MACVLAN_MACADDR_SET) parameter, lower device already has a macvlan port and register_netdevice() called from macvlan_common_newlink() fails (e.g. because of the invalid link name). In this case macvlan_hash_add_source is called from macvlan_change_sources() / macvlan_common_newlink(): This adds a reference to vlan to the port's vlan_source_hash using macvlan_source_entry. vlan is a pointer to the priv data of the link that is being created. When register_netdevice() fails, the error is returned from macvlan_newlink() to rtnl_newlink_create(): if (ops->newlink) err = ops->newlink(dev, ¶ms, extack); else err = register_netdevice(dev); if (err With all that, my fix is to make sure we call macvlan_flush_sources() regardless of @create value whenever "goto destroy_macvlan_port;" path is taken. Many thanks to valis for following up on this issue.

Affected

77 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= aa5fd0fb77486b8a6764ead8627baa14790e4280 < da5c6b8ae47e414be47e5e04def15b25d5c962dcda5c6b8ae47e414be47e5e04def15b25d5c962dc
linuxlinux>= aa5fd0fb77486b8a6764ead8627baa14790e4280 < 5dae6b36a7cb7a4fcf4121b95e9ca7f96f816c8a5dae6b36a7cb7a4fcf4121b95e9ca7f96f816c8a
linuxlinux>= aa5fd0fb77486b8a6764ead8627baa14790e4280 < c43d0e787cbba569ec9d11579ed370b50fab6c9cc43d0e787cbba569ec9d11579ed370b50fab6c9c
linuxlinux>= aa5fd0fb77486b8a6764ead8627baa14790e4280 < 11ba9f0dc865136174cb98834280fb21bbc950c711ba9f0dc865136174cb98834280fb21bbc950c7
linuxlinux>= aa5fd0fb77486b8a6764ead8627baa14790e4280 < 986967a162142710076782d5b93daab93a892980986967a162142710076782d5b93daab93a892980
linuxlinux>= aa5fd0fb77486b8a6764ead8627baa14790e4280 < cdedcd5aa3f3cb8b7ae0f87ab3a936d0bd583d66cdedcd5aa3f3cb8b7ae0f87ab3a936d0bd583d66
linuxlinux>= aa5fd0fb77486b8a6764ead8627baa14790e4280 < f8db6475a83649689c087a8f52486fcc53e627e9f8db6475a83649689c087a8f52486fcc53e627e9
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 4.9.1 < 5.10.2505.10.250
linuxlinux_kernel>= 5.11 < 5.15.2005.15.200
linuxlinux_kernel>= 5.16 < 6.1.1636.1.163
linuxlinux_kernel>= 6.13 < 6.18.106.18.10
linuxlinux_kernel>= 6.2 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.