PatchSiren cyber security CVE debrief
CVE-2026-23284 Linux CVE debrief
CVE-2026-23284 is a Linux kernel bug in the mtk_eth_soc Ethernet driver’s XDP setup error path. According to the fixed description, if mtk_open fails during mtk_xdp_setup(), the code should restore the previous eBPF program pointer and avoid dropping its reference count. The published record ties the issue to multiple upstream/stable kernel fixes and rates it MEDIUM severity with primary availability impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Kernel maintainers, distro security teams, and operators running Linux kernels that include the MediaTek Ethernet driver (mtk_eth_soc), especially on systems that use XDP/eBPF features. Environments that rely on stable kernel update branches listed in the advisory should prioritize review and patching.
Technical summary
The vulnerability is an error-handling defect in mtk_xdp_setup(). On setup failure, the driver is supposed to revert prog to old_prog and not decrement the old program’s refcount. If it fails to do so, the kernel can be left with an incorrect eBPF program pointer and a reference-count mismatch in the driver state. NVD assigns CVSS 3.1 vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and does not provide a more specific CWE than NVD-CWE-noinfo.
Defensive priority
Medium. The issue is locally reachable and requires low privileges, but NVD rates the potential impact as high availability loss. Patch priority is strongest for systems using the affected MediaTek Ethernet driver and any deployment that enables or depends on XDP/eBPF paths.
Recommended defensive actions
- Apply the relevant Linux kernel fixes referenced by NVD and move to a kernel build that includes the upstream/stable patch for this issue.
- If you maintain a downstream kernel, verify that the mtk_xdp_setup() failure path restores old_prog and preserves the correct reference count handling.
- Prioritize patch validation on systems that use MediaTek Ethernet hardware and XDP/eBPF features.
- Track vendor kernel update branches that correspond to the affected version ranges listed by NVD: 6.0 before 6.1.167, 6.2 before 6.6.130, 6.7 before 6.12.77, 6.13 before 6.18.17, and 6.19 before 6.19.7.
Evidence notes
The debrief is based on the CVE description and NVD record only. NVD lists the vulnerability as analyzed, with CVSS 5.5 and vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The record includes multiple official kernel.org patch references, and the description explicitly says to reset the eBPF program pointer to old_prog and avoid decreasing its refcount if mtk_open fails in mtk_xdp_setup(). No exploit details beyond the supplied corpus are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23284 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23284
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23284 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23284
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0abc73c8a40fd64ac1739c90bb4f42c418d27a5e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/29629dd7d37349e9fb605375a75de44ac8926ea9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6f95b59520278a72df9905db791b7ea31375fbc1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8c2d76a9658a4dbfcf02f2693a97e2d5ff42197a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b73dfe1ea7be7a072482434643b517d7726f4c8d
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ff14cd44c85c20ad69479db73698185de291550c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.