cbcvebase.
CVE-2026-23384
published 2026-03-25

CVE-2026-23384: In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Fix kernel stack leak in ionic_create_cq() struct ionic_cq_resp resp { __u32…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.6th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Fix kernel stack leak in ionic_create_cq() struct ionic_cq_resp resp { __u32 cqid[2]; // offset 0 - PARTIALLY SET (see below) __u8 udma_mask; // offset 8 - SET (resp.udma_mask = vcq->udma_mask) __u8 rsvd[7]; // offset 9 - NEVER SET udma_mask & BIT(udma_idx)). The array has 2 entries but udma_count could be 1, meaning cqid[1] might never be written via ionic_create_cq_common(). If udma_mask only has bit 0 set, cqid[1] (4 bytes) is also leaked. So potentially 11 bytes leaked.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= e8521822c733c6deab0f339843cd37cd62c12795 < a6f3e0fa8e862f220c26c2f27e5ddc42eb82ad3ea6f3e0fa8e862f220c26c2f27e5ddc42eb82ad3e
linuxlinux>= e8521822c733c6deab0f339843cd37cd62c12795 < 547d0b07ad73915b323bc21f85c5d3252bebbbcf547d0b07ad73915b323bc21f85c5d3252bebbbcf
linuxlinux>= e8521822c733c6deab0f339843cd37cd62c12795 < faa72102b178c7ae6c6afea23879e7c84fc59b4efaa72102b178c7ae6c6afea23879e7c84fc59b4e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 6.18.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.18.1 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.