PatchSiren cyber security CVE debrief
CVE-2026-23449 Linux CVE debrief
CVE-2026-23449 is a Linux kernel double-free in TEQL qdisc handling. NVD rates it HIGH (CVSS 7.8), and the issue is described as a race between TEQL's datapath and qdisc reset logic when a TEQL device has a lockless root qdisc. The reported effect is kernel memory corruption and crashes, including a KASAN double-free report. Fixed kernels are referenced by upstream stable patches and NVD marks multiple Linux kernel release ranges as affected.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Linux kernel maintainers, distro security teams, and operators running systems that use TEQL (Traffic Equalizer) qdiscs, especially where local users or privileged workloads can interact with networking stack configuration. Fleet owners should pay attention to the affected kernel version ranges listed by NVD.
Technical summary
The vulnerability is identified as CWE-415 (double free). According to the source description, teql_master_xmit can race with qdisc_reset when a TEQL device has a lockless qdisc as root; qdisc_reset is supposed to be called under seq_lock to avoid racing with the datapath. The provided crash trace shows the double-free surfacing in skb_release_data via pfifo_fast_reset, qdisc_reset, teql_destroy, and qdisc_graft. NVD lists the following affected Linux kernel ranges: 4.18 through 6.1.167, 6.2 through 6.6.130, 6.7 through 6.12.78, 6.13 through 6.18.20, 6.19 through 6.19.10, and 7.0-rc1 through 7.0-rc4.
Defensive priority
High for environments that use TEQL or otherwise expose the affected networking path; moderate otherwise because the issue requires local access and is not reported as remotely exploitable in the supplied data.
Recommended defensive actions
- Apply the upstream/stable kernel fixes referenced by NVD and the kernel patch links.
- Upgrade to a kernel version outside the affected ranges listed by NVD.
- Review whether TEQL is enabled or used in your environment; if not needed, disable or avoid TEQL configurations.
- Prioritize patching systems that allow untrusted local users, containers, or privileged workloads to reach the affected networking stack paths.
- Watch for kernel crashes or KASAN double-free reports involving skb_release_data, qdisc_reset, teql_destroy, or qdisc_graft on affected builds.
Evidence notes
This debrief uses only the supplied CVE/NVD corpus and official kernel patch references. Supported facts include the CVE ID, CVSS 7.8/High, CWE-415, the TEQL/qdisc_reset race description, the crash trace indicating a double-free in skb_release_data, and the affected version ranges listed in NVD. No exploit steps, payloads, or unstated root-cause details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23449 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23449
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23449 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23449
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/21c89a0a8de7eadad8d385645a95b3233f23130e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4a233447b941db451ea5f5a0942cffd0f7f7eaae
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4e8ebc4c18ea8213d28e6cb867d18fcc67daca21
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/66360460cab63c248ca5b1070a01c0c29133b960
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/afbc79a7770b230a9f24bd39271209d6b3682c5f
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e9c66d3e7d8557b3308e55c613aa07254fe97611
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.