cbcvebase.
CVE-2026-23389
published 2026-03-25

CVE-2026-23389: In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice_set_ringparam, tx_rings and xdp_rings…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice_set_ringparam, tx_rings and xdp_rings are allocated before rx_rings. If the allocation of rx_rings fails, the code jumps to the done label leaking both tx_rings and xdp_rings. Furthermore, if the setup of an individual Rx ring fails during the loop, the code jumps to the free_tx label which releases tx_rings but leaks xdp_rings. Fix this by introducing a free_xdp label and updating the error paths to ensure both xdp_rings and tx_rings are properly freed if rx_rings allocation or setup fails. Compile tested only. Issue found using a prototype static analysis tool and code review.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= fcea6f3da546b93050f3534aadea7bd96c1d7349 < bddf04e3822e4fa38691433dd0750420d49a0dd6bddf04e3822e4fa38691433dd0750420d49a0dd6
linuxlinux>= fcea6f3da546b93050f3534aadea7bd96c1d7349 < e0c211a0c26159058303712d6b4fbd1c88835e6de0c211a0c26159058303712d6b4fbd1c88835e6d
linuxlinux>= fcea6f3da546b93050f3534aadea7bd96c1d7349 < b23282218eca27b710111460b4964c8a456c6c44b23282218eca27b710111460b4964c8a456c6c44
linuxlinux>= fcea6f3da546b93050f3534aadea7bd96c1d7349 < 63dc317dfcd3faffd082c2bf3080f9ad070273da63dc317dfcd3faffd082c2bf3080f9ad070273da
linuxlinux>= fcea6f3da546b93050f3534aadea7bd96c1d7349 < 44ba32a892b72de3faa04b8cfb1f2f1418fdd58044ba32a892b72de3faa04b8cfb1f2f1418fdd580
linuxlinux>= fcea6f3da546b93050f3534aadea7bd96c1d7349 < fe868b499d16f55bbeea89992edb98043c9de416fe868b499d16f55bbeea89992edb98043c9de416
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 4.17.0 < 6.19.76.19.7
linuxlinux_kernel>= 4.17.1 < 6.12.816.12.81
linuxlinux_kernel>= 6.13 < 6.18.226.18.22
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc6.2MEDIUM
vendor_redhat5.5LOW
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.