CVE-2026-23001
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23001 is a Use-After-Free (UAF) vulnerability in the Linux kernel's macvlan network driver, specifically within the macvlan_forward_source() function. It was published on January 25, 2026, and affects Linux kernel versions from 3.18.1 through 5.10.248, 5.11 through 5.15.198, 5.16 through 6.1.161, 6.2 through 6.6.121, 6.7 through 6.12.66, and 6.13 through 6.18.6, as well as pre-release versions 6.19-rc1 through 6.19-rc8. IBM Cloud Pak for Data System is also listed as an affected product. It carries a CVSS v3.1 base score of 7.8 (High), assigned by kernel.org (Red Hat CVE, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and stems from improper RCU (Read-Copy-Update) synchronization in the macvlan driver. Specifically, when macvlan_hash_del_source() is called to remove a source MAC address entry, the entry->vlan pointer within the macvlan_source_entry structure is not cleared before the RCU grace period begins. This creates a race condition where macvlan_forward_source() — which processes incoming packets — can dereference the already-freed vlan pointer, leading to a UAF condition. Exploitation requires local access with low privileges, as an attacker must be able to trigger the relevant network path (e.g., by manipulating macvlan source entries) while a concurrent deletion is in progress (Red Hat CVE, Red Hat Bugzilla).

Impact

Successful exploitation of this vulnerability by a local, low-privileged attacker could result in kernel memory corruption, system crash (denial of service), or potentially arbitrary code execution with kernel privileges. All three security dimensions are affected: confidentiality (kernel memory disclosure), integrity (memory corruption), and availability (system crash). In containerized or multi-tenant environments using macvlan networking, this could enable privilege escalation or lateral movement between workloads (Red Hat CVE, Feedly).

Mitigation and workarounds

Patches are available in the stable Linux kernel repositories. The fixed versions are: 5.10.249+, 5.15.199+, 6.1.162+, 6.6.122+, 6.12.67+, and 6.18.7+. Patch commits include 15f6faf36e, 232afc74a6, 484919832e, 6dbead9c76, 7470a7a63d, 8133e85b8a, and 8518712a2c at git.kernel.org. Red Hat has addressed this issue across RHEL 8, 9, and 10 via multiple errata (RHSA-2026:3963, RHSA-2026:3964, RHSA-2026:3966, RHSA-2026:4012, and others). Ubuntu, AlmaLinux, Rocky Linux, Oracle Linux, SUSE, and Amazon Linux 2 have also released updated kernel packages. Organizations should apply the latest stable kernel update for their distribution branch as the primary remediation; no configuration-based workaround is available (Red Hat Bugzilla, Red Hat CVE).

Community reactions

Red Hat triaged this as medium severity and issued multiple errata across RHEL 8, 9, and 10 product lines. The vulnerability was reported to the kernel security team via the linux-cve-announce mailing list and discussed in the netdev kernel mailing list. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking and distribution advisory channels.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management