PatchSiren cyber security CVE debrief
CVE-2026-23313 Linux CVE debrief
A preempt count leak vulnerability exists in the Linux kernel's i40e driver, specifically within the NAPI poll tracepoint. The issue stems from using get_cpu() in a tracepoint assignment without a corresponding put_cpu() call, causing the preempt count to increment without decrement. This results in a softirq warning indicating mismatched preempt counts on entry and exit of NET_RX softirq processing. The vulnerability affects multiple Linux kernel versions from 6.2 through 7.0-rc2. The fix replaces get_cpu() with smp_processor_id(), which does not manipulate the preempt count. This is a local denial-of-service condition with medium severity.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-25
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-03-25
- Advisory updated
- 2026-05-26
Who should care
Linux system administrators operating kernels 6.2+ with Intel i40e network adapters; organizations running network-intensive workloads with kernel tracepoints enabled; security teams monitoring for local denial-of-service vectors in kernel networking subsystems
Technical summary
The i40e driver's NAPI poll tracepoint uses get_cpu() to obtain the current CPU ID for tracing purposes. This function increments the preempt count but lacks a matching put_cpu() call, causing a preempt count leak. The leak manifests as a kernel warning when softirq exits with a higher preempt count than entry. The fix substitutes smp_processor_id(), which retrieves the CPU ID without preempt count manipulation. Affected code paths involve network receive processing (NET_RX softirq) on systems with Intel i40e adapters. Exploitation requires local access to trigger network receive operations under tracepoint-enabled conditions, leading to potential system instability or denial of service through preempt count corruption.
Defensive priority
medium
Recommended defensive actions
- Apply kernel patches from stable branches (6.6.136+, 6.12.77+, 6.18.17+, 6.19.7+) or mainline 7.0-rc3+ when available
- Monitor kernel logs for softirq preempt count mismatch warnings as indicators of trigger conditions
- Prioritize patching systems with Intel i40e network adapters where NAPI polling and tracepoints are active
- Validate preempt count stability through kernel testing after patch application
- Review custom kernel configurations enabling i40e driver tracepoints for exposure assessment
Evidence notes
CVE published 2026-03-25; modified 2026-05-26. Kernel patches available for stable branches 6.6, 6.12, 6.18, 6.19, and mainline. CPE criteria confirm affected versions: 6.2-6.6.135, 6.7-6.12.76, 6.13-6.18.16, 6.19-6.19.6, and 7.0-rc1/rc2.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23313 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23313
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23313 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23313
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4b3d54a85bd37ebf2d9836f0d0de775c0ff21af9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9e0f091821571f0da387462803ee42f0bb157582
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b7e91827e1cf89cd34ad11dc8f8c010b70ab786e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/dca4ea596a3b0a1b82bc1d9f3e4d88bd9ad9561f
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fa5d5baf67f619c7aa70697a194b5a9edd9f5bb7
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.