PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23171 Linux CVE debrief

CVE-2026-23171 is a Linux kernel bonding vulnerability that can trigger a use-after-free during enslave handling. According to the CVE description, the problem occurs when a new slave is added to the slave array before all enslave error paths are finished; if enslave then fails, cleanup can free the slave memory while it may still be used for transmit path decisions. The fix moves the slave-array update later in the flow, after XDP setup, so further enslave failures are not expected at that point. NVD rates the issue CVSS 3.1 7.8 HIGH with local attack requirements (AV:L/PR:L/UI:N) and maps it to CWE-416. The vulnerable range listed by NVD covers Linux kernel 5.15 through 6.18.9, plus 6.19-rc1 through 6.19-rc7.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-14
Original CVE updated
2026-05-17
Advisory published
2026-02-14
Advisory updated
2026-05-17

Who should care

Linux kernel maintainers, distribution security teams, and operators using bonding interfaces—especially environments that enable XDP on bonded devices or allow local users to change network configuration. Systems running kernels in the affected ranges should treat this as a prompt patching item.

Technical summary

The bug is in bonding enslave processing. The CVE text says the new slave is inserted into the slave array too early, before the code has finished handling failure cases. Because the slave can be selected for transmit immediately, a later enslave error path can free the allocated slave memory while transmit code still references it, creating a use-after-free. The kernel fix reorders the operations so the slave-array update happens after XDP setup, when no further enslave failures are expected. The NVD record associates the issue with CWE-416 and affected Linux kernel versions from 5.15 up to 6.18.9, plus 6.19-rc1 through 6.19-rc7.

Defensive priority

High for systems that use Linux bonding. Patch quickly if you run affected kernels, particularly where bonded interfaces and XDP are in use or where local users can manipulate network device membership.

Recommended defensive actions

  • Apply the kernel fix from the referenced stable patches or update to a kernel release that includes the remediation.
  • Prioritize systems running Linux kernel 5.15 through 6.18.9 and 6.19-rc1 through 6.19-rc7.
  • Review hosts that use bonded interfaces, especially those with XDP attached to bond devices.
  • Monitor for kernel crashes or instability involving bonding transmit paths if patching is not immediately possible.
  • Use the official CVE and NVD records to confirm whether your deployed kernel build contains the fix.

Evidence notes

The CVE description states: 'bonding: fix use-after-free due to enslave fail after slave array update' and explains that the slave-array update must be moved after XDP setup to avoid freeing memory that may still be used for Tx. The description also includes a reproducible crash scenario and a kernel stack trace showing failure in netdev_core_pick_tx and bond_start_xmit. NVD lists the issue as CWE-416, CVSS 3.1 7.8 HIGH, and vulnerable Linux kernel versions 5.15 through 6.18.9 plus 6.19-rc1 through 6.19-rc7. Publication date used here is the CVE published timestamp, 2026-02-14T16:15:57.353Z; the 2026-05-17 timestamp reflects a later modification to the record.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23171 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23171

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23171 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23171

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/172dcb67dd35b162357df229d7806acc724cd469

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2889d92c5f728351c9930c7996d22fe6e906e785

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bd25b092a06a3e05f7e8bd6da6fa7318777d8c3d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e9acda52fd2ee0cdca332f996da7a95c5fd25294

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.