PatchSiren cyber security CVE debrief
CVE-2026-23083 Linux CVE debrief
A HIGH severity vulnerability was found in the Linux kernel, affecting the FOU_ATTR_IPPROTO. This issue has been resolved through a series of patches. The vulnerability allows an attacker to potentially cause a denial of service or execute arbitrary code. Users are advised to update to the latest kernel version to mitigate this vulnerability. The Common Vulnerabilities and Exposures (CVE) score for this vulnerability is 7.8, indicating a high level of severity. System administrators should be aware of this vulnerability and take necessary actions to update their systems. The vulnerability is related to the FOU_ATTR_IPPROTO in the Linux kernel. If FOU_ATTR_IPPROTO is set to 0, the skb is not freed by fou_udp_recv() nor 'resubmit'-ted in ip_protocol_deliver_rcu().
- Vendor
- Linux
- Product
- Unknown
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
System administrators and users of the Linux kernel should be aware of this vulnerability and take necessary actions to update their systems. The vulnerability has a high CVSS score of 7.8, indicating a high level of severity. Users of the Linux kernel should review their systems and apply the necessary patches to mitigate this vulnerability. The vulnerability affects the FOU_ATTR_IPPROTO in the Linux kernel and can be mitigated by updating to the latest kernel version.
Technical summary
The vulnerability is related to the FOU_ATTR_IPPROTO in the Linux kernel. If FOU_ATTR_IPPROTO is set to 0, the skb is not freed by fou_udp_recv() nor 'resubmit'-ted in ip_protocol_deliver_rcu(). This issue has been addressed through multiple patches available in the kernel's stable branches. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. The issue affects the Linux kernel and can be mitigated by updating to the latest kernel version. The vulnerability allows an attacker to potentially cause a denial of service or execute arbitrary code.
Defensive priority
High priority should be given to updating the Linux kernel to the latest version, especially for systems that utilize FOU_ATTR_IPPROTO. System administrators should review their systems and apply the necessary patches to mitigate this vulnerability.
Recommended defensive actions
- Update the Linux kernel to the latest version
- Apply the available patches
- Monitor system updates and security advisories
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-02-04T17:16:19.163Z and last modified on 2026-07-14T13:18:23.673Z. The NVD entry is currently Modified. This vulnerability affects the Linux kernel, specifically the FOU_ATTR_IPPROTO. If FOU_ATTR_IPPROTO is set to 0, the skb is not freed by fou_udp_recv() nor 'resubmit'-ted in ip_protocol_deliver_rcu(). The issue has been addressed through multiple patches available in the kernel's stable branches. Users are advised to update to the latest kernel version to mitigate this vulnerability. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23083 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23083
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23083 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23083
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1cc98b8887cabb1808d2f4a37cd10a7be7574771
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/611ef4bd9c73d9e6d87bed57a635ff1fdd8c91ea
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6e983789b7588ee59cbf303583546c043bad8e19
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7a9bc9e3f42391e4c187e099263cf7a1c4b69ff5
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9b75dff8446ec871030d8daf5a69e74f5fe8b956
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b7db31a52c3862a1a32202a273a4c32e7f5f4823
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c7498f9bc390479ccfad7c7f2332237ff4945b03
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.