
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23122 is a vulnerability in the Linux kernel's igc (Intel I225/I226 Ethernet) driver related to improper TSN (Time-Sensitive Networking) TX packet buffer sizing. The root cause is that a 7 KB per-queue TX buffer allocation causes TX unit hangs under heavy timestamping load; the fix reduces this to 5 KB per queue, aligning with the I225/I226 SW User Manual Section 7.5.4 recommendation. Affected versions include Linux kernel 6.16 through 6.18.7 and release candidates 6.19-rc1 through 6.19-rc6. It was published on February 14, 2026, with patches added on March 18, 2026. The CVSS v3.1 base score is 5.5 (Medium) (Feedly, Tenable).
The vulnerability is classified under availability impact (CWE category: resource exhaustion / improper resource management) in the igc network driver. When the TX packet buffer is set to 7 KB per queue, the hardware TX unit can hang under heavy TSN timestamping workloads, causing a denial-of-service condition for the affected network interface. Exploitation requires local access with low privileges — an attacker or process generating heavy TSN timestamping traffic on an affected system could trigger the hang. The fix, committed to the stable kernel tree, reduces the per-queue buffer to 5 KB, freeing 8 KB that was previously unused, without impacting throughput since the i226 is PCIe-limited for small TSN packets (Feedly, Kernel Patch 1, Kernel Patch 2).
Successful exploitation results in a TX unit hang in the igc network driver, causing a loss of network availability (denial of service) on systems using Intel I225/I226 Ethernet adapters under heavy TSN timestamping load. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Affected systems include those running Linux kernel 6.16–6.18.7 or 6.19-rc1 through rc6 with igc-based NICs in TSN configurations (Feedly).
The Linux kernel maintainers have released patches addressing this issue in stable kernel versions. Users should update to Linux kernel 6.18.8 or later, which includes the fix reducing the TSN TX packet buffer from 7 KB to 5 KB per queue. The patches are available at the official kernel stable tree. No configuration-based workaround is documented; upgrading the kernel is the recommended remediation (Kernel Patch 1, Kernel Patch 2, Tenable).
Coverage of CVE-2026-23122 has been limited to automated vulnerability tracking platforms and security feeds, with no notable vendor statements or researcher commentary beyond the kernel commit itself. The Yocto Project security mailing list referenced the issue in the context of embedded Linux security tracking (Yocto Security List).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."