cbcvebase.
CVE-2026-23326
published 2026-03-25

CVE-2026-23326: In the Linux kernel, the following vulnerability has been resolved: xsk: Fix fragment node deletion to prevent buffer leak After commit b692bf9a7543 ("xsk: Get…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: xsk: Fix fragment node deletion to prevent buffer leak After commit b692bf9a7543 ("xsk: Get rid of xdp_buff_xsk::xskb_list_node"), the list_node field is reused for both the xskb pool list and the buffer free list, this causes a buffer leak as described below. xp_free() checks if a buffer is already on the free list using list_empty(&xskb->list_node). When list_del() is used to remove a node from the xskb pool list, it doesn't reinitialize the node pointers. This means list_empty() will return false even after the node has been removed, causing xp_free() to incorrectly skip adding the buffer to the free list. Fix this by using list_del_init() instead of list_del() in all fragment handling paths, this ensures the list node is reinitialized after removal, allowing the list_empty() to work correctly.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 560c974b7ccd95bb9ff20df77f6654283e45c9c6 < 5172adf9efb8298a52f4dcdc3f98d4d9d1e06a6d5172adf9efb8298a52f4dcdc3f98d4d9d1e06a6d
linuxlinux>= b692bf9a7543af7ad11a59d182a3757578f0ba53 < 645c6d8376ad4913cbffe0e0c2cca0c4febbe596645c6d8376ad4913cbffe0e0c2cca0c4febbe596
linuxlinux>= b692bf9a7543af7ad11a59d182a3757578f0ba53 < b38cbd4af5034635cff109e08788c63f956f3a69b38cbd4af5034635cff109e08788c63f956f3a69
linuxlinux>= b692bf9a7543af7ad11a59d182a3757578f0ba53 < 60abb0ac11dccd6b98fd9182bc5f85b62168886160abb0ac11dccd6b98fd9182bc5f85b621688861
linuxlinux>= fd5614763805d6f386bd07cc53558f88b1b1eb62 < 2a9ea988465ece5b6896b1bdc144170a64e84c352a9ea988465ece5b6896b1bdc144170a64e84c35
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.1 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.