PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23449 Linux CVE debrief

CVE-2026-23449 is a Linux kernel double-free in TEQL qdisc handling. NVD rates it HIGH (CVSS 7.8), and the issue is described as a race between TEQL's datapath and qdisc reset logic when a TEQL device has a lockless root qdisc. The reported effect is kernel memory corruption and crashes, including a KASAN double-free report. Fixed kernels are referenced by upstream stable patches and NVD marks multiple Linux kernel release ranges as affected.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Linux kernel maintainers, distro security teams, and operators running systems that use TEQL (Traffic Equalizer) qdiscs, especially where local users or privileged workloads can interact with networking stack configuration. Fleet owners should pay attention to the affected kernel version ranges listed by NVD.

Technical summary

The vulnerability is identified as CWE-415 (double free). According to the source description, teql_master_xmit can race with qdisc_reset when a TEQL device has a lockless qdisc as root; qdisc_reset is supposed to be called under seq_lock to avoid racing with the datapath. The provided crash trace shows the double-free surfacing in skb_release_data via pfifo_fast_reset, qdisc_reset, teql_destroy, and qdisc_graft. NVD lists the following affected Linux kernel ranges: 4.18 through 6.1.167, 6.2 through 6.6.130, 6.7 through 6.12.78, 6.13 through 6.18.20, 6.19 through 6.19.10, and 7.0-rc1 through 7.0-rc4.

Defensive priority

High for environments that use TEQL or otherwise expose the affected networking path; moderate otherwise because the issue requires local access and is not reported as remotely exploitable in the supplied data.

Recommended defensive actions

  • Apply the upstream/stable kernel fixes referenced by NVD and the kernel patch links.
  • Upgrade to a kernel version outside the affected ranges listed by NVD.
  • Review whether TEQL is enabled or used in your environment; if not needed, disable or avoid TEQL configurations.
  • Prioritize patching systems that allow untrusted local users, containers, or privileged workloads to reach the affected networking stack paths.
  • Watch for kernel crashes or KASAN double-free reports involving skb_release_data, qdisc_reset, teql_destroy, or qdisc_graft on affected builds.

Evidence notes

This debrief uses only the supplied CVE/NVD corpus and official kernel patch references. Supported facts include the CVE ID, CVSS 7.8/High, CWE-415, the TEQL/qdisc_reset race description, the crash trace indicating a double-free in skb_release_data, and the affected version ranges listed in NVD. No exploit steps, payloads, or unstated root-cause details are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23449 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23449

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23449 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23449

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/21c89a0a8de7eadad8d385645a95b3233f23130e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4a233447b941db451ea5f5a0942cffd0f7f7eaae

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4e8ebc4c18ea8213d28e6cb867d18fcc67daca21

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/66360460cab63c248ca5b1070a01c0c29133b960

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/afbc79a7770b230a9f24bd39271209d6b3682c5f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e9c66d3e7d8557b3308e55c613aa07254fe97611

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.