PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23313 Linux CVE debrief

A preempt count leak vulnerability exists in the Linux kernel's i40e driver, specifically within the NAPI poll tracepoint. The issue stems from using get_cpu() in a tracepoint assignment without a corresponding put_cpu() call, causing the preempt count to increment without decrement. This results in a softirq warning indicating mismatched preempt counts on entry and exit of NET_RX softirq processing. The vulnerability affects multiple Linux kernel versions from 6.2 through 7.0-rc2. The fix replaces get_cpu() with smp_processor_id(), which does not manipulate the preempt count. This is a local denial-of-service condition with medium severity.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-25
Original CVE updated
2026-05-26
Advisory published
2026-03-25
Advisory updated
2026-05-26

Who should care

Linux system administrators operating kernels 6.2+ with Intel i40e network adapters; organizations running network-intensive workloads with kernel tracepoints enabled; security teams monitoring for local denial-of-service vectors in kernel networking subsystems

Technical summary

The i40e driver's NAPI poll tracepoint uses get_cpu() to obtain the current CPU ID for tracing purposes. This function increments the preempt count but lacks a matching put_cpu() call, causing a preempt count leak. The leak manifests as a kernel warning when softirq exits with a higher preempt count than entry. The fix substitutes smp_processor_id(), which retrieves the CPU ID without preempt count manipulation. Affected code paths involve network receive processing (NET_RX softirq) on systems with Intel i40e adapters. Exploitation requires local access to trigger network receive operations under tracepoint-enabled conditions, leading to potential system instability or denial of service through preempt count corruption.

Defensive priority

medium

Recommended defensive actions

  • Apply kernel patches from stable branches (6.6.136+, 6.12.77+, 6.18.17+, 6.19.7+) or mainline 7.0-rc3+ when available
  • Monitor kernel logs for softirq preempt count mismatch warnings as indicators of trigger conditions
  • Prioritize patching systems with Intel i40e network adapters where NAPI polling and tracepoints are active
  • Validate preempt count stability through kernel testing after patch application
  • Review custom kernel configurations enabling i40e driver tracepoints for exposure assessment

Evidence notes

CVE published 2026-03-25; modified 2026-05-26. Kernel patches available for stable branches 6.6, 6.12, 6.18, 6.19, and mainline. CPE criteria confirm affected versions: 6.2-6.6.135, 6.7-6.12.76, 6.13-6.18.16, 6.19-6.19.6, and 7.0-rc1/rc2.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23313 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23313

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23313 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23313

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4b3d54a85bd37ebf2d9836f0d0de775c0ff21af9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9e0f091821571f0da387462803ee42f0bb157582

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b7e91827e1cf89cd34ad11dc8f8c010b70ab786e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/dca4ea596a3b0a1b82bc1d9f3e4d88bd9ad9561f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fa5d5baf67f619c7aa70697a194b5a9edd9f5bb7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.