cbcvebase.
CVE-2026-23262
published 2026-03-18

CVE-2026-23262: In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count change The driver and the NIC share a…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count change The driver and the NIC share a region in memory for stats reporting. The NIC calculates its offset into this region based on the total size of the stats region and the size of the NIC's stats. When the number of queues is changed, the driver's stats region is resized. If the queue count is increased, the NIC can write past the end of the allocated stats region, causing memory corruption. If the queue count is decreased, there is a gap between the driver and NIC stats, leading to incorrect stats reporting. This change fixes the issue by allocating stats region with maximum size, and the offset calculation for NIC stats is changed to match with the calculation of the NIC.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c < f432f7613c220db32c2c6942420daf7b3f2e7d7ef432f7613c220db32c2c6942420daf7b3f2e7d7e
linuxlinux>= 24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c < 9d93332397405b62a3300b22d04ac65d990b91ff9d93332397405b62a3300b22d04ac65d990b91ff
linuxlinux>= 24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c < 837c662f47dac43efa1aef2dd433c6b4b4c073af837c662f47dac43efa1aef2dd433c6b4b4c073af
linuxlinux>= 24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c < df54838ab61826ecc1a562ffa5e280c3ab7289a7df54838ab61826ecc1a562ffa5e280c3ab7289a7
linuxlinux>= 24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c < 9fa0a755db3e1945fe00f73fe27d85ef6c8818b79fa0a755db3e1945fe00f73fe27d85ef6c8818b7
linuxlinux>= 24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c < 11f8311f69e4c361717371b4901ff92daeb76e9c11f8311f69e4c361717371b4901ff92daeb76e9c
linuxlinux>= 24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c < 7b9ebcce0296e104a0d82a6b09d68564806158ff7b9ebcce0296e104a0d82a6b09d68564806158ff
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 5.10 < 5.10.2505.10.250
linuxlinux_kernel>= 5.10.0 < 5.10.2505.10.250
linuxlinux_kernel>= 5.11 < 5.15.2005.15.200
linuxlinux_kernel>= 5.11.0 < 5.15.2005.15.200
linuxlinux_kernel>= 5.16 < 6.1.1636.1.163
linuxlinux_kernel>= 5.16.0 < 6.1.1636.1.163
linuxlinux_kernel>= 6.13 < 6.18.106.18.10
linuxlinux_kernel>= 6.13.0 < 6.18.106.18.10
linuxlinux_kernel>= 6.2 < 6.6.1246.6.124
linuxlinux_kernel>= 6.2.0 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7 < 6.12.706.12.70

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.