PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23441 Linux CVE debrief

A race condition exists in the Linux kernel's net/mlx5e due to concurrent access to IPSec ASO context. The driver uses a single mlx5e_ipsec_aso struct for each PF, containing a shared DMA-mapped context for all ASO operations. A second operation can overwrite the shared context before the first operation's completion is processed, leading to unexpected behavior. This vulnerability affects Linux kernel versions 6.2.1 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10, and 7.0 rc1 to rc7.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 4.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Linux kernel versions 6.2.1 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10, and 7.0 rc1 to rc7 should apply patches to prevent exploitation. This includes operators managing Linux-based systems, platform administrators, vulnerability management teams, and security teams responsible for maintaining system integrity and security.

Technical summary

The Linux kernel's net/mlx5e has a vulnerability due to a race condition in IPSec ASO context access. The driver shares a DMA-mapped context for ASO operations, allowing a second operation to corrupt the context before the first operation completes, resulting in unexpected behavior. This affects Linux kernel versions 6.2.1 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10, and 7.0 rc1 to rc7, and requires patches to fix the race condition.

Defensive priority

Apply patches to fix the race condition in IPSec ASO context access. Prioritize patching for Linux kernel versions 6.2.1 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10, and 7.0 rc1 to rc7. Monitor for potential exploitation attempts and review system logs for suspicious activity related to IPSec ASO operations. Consider implementing compensating controls for exposed systems while remediation is scheduled and verified. Track exceptions and retest remediated assets to ensure the vulnerability is properly addressed. Perform an asset inventory to identify potentially affected systems and prioritize patching based on risk and exposure. Implement source tracking to monitor for potential exploitation attempts and adjust defensive priorities accordingly. Review relevant monitoring, detection, and logs for exposed assets that need extra review. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Close the item only after evidence is documented that the vulnerability has been properly addressed.

Recommended defensive actions

  • Apply patches from https://git.kernel.org/stable/c/2c6a5be0aee5a44066f68a332c30650900e32ad4
  • Apply patches from https://git.kernel.org/stable/c/6834d196107d5267dcad31b44211da7698e8f618
  • Apply patches from https://git.kernel.org/stable/c/99aaee927800ea00b441b607737f9f67b1899755
  • Apply patches from https://git.kernel.org/stable/c/99b36850d881e2d65912b2520a1c80d0fcc9429a
  • Apply patches from https://git.kernel.org/stable/c/c3db55dc0f3344b62da25b025a8396d78763b5fa

Evidence notes

The CVE record was published on 2026-04-03T16:16:26.340Z and has not been modified since then. The NVD entry is currently Analyzed. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the official advisory.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T16:16:26.340Z and has not been modified since then.