Junglewise Threat Intelligence

CVE-2026-23262: Linux Kernel gve driver out-of-bounds write in stats reporting

CVE-2026-23262 · Severity: info · CVSS 7.8 · Published 2026-03-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Google Virtual Ethernet (gve) driver for the Linux kernel could allow for memory corruption. The driver manages network traffic for virtual machines, and a flaw in how it reports performance statistics can cause the system to write data into unintended memory locations when network settings are changed. This could lead to system instability, crashes, or potentially unauthorized access to sensitive information.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the Linux kernel's Google Virtual Ethernet (gve) driver. The driver and the Network Interface Card (NIC) share a memory region for statistics reporting. When the number of network queues is increased, the driver resizes this region, but the NIC may calculate offsets based on stale or mismatched size assumptions, leading it to write past the end of the allocated buffer. Conversely, decreasing the queue count causes offset gaps and incorrect reporting. An attacker with local access could potentially exploit this memory corruption to cause a denial of service or escalate privileges. The issue has been resolved by ensuring the stats region is allocated with the maximum possible size and synchronizing offset calculations between the driver and the NIC.

Affected products

  • Linux Linux Kernel 5.10 to 5.10.250, 5.11 to 5.15.200, 5.16 to 6.1.163, 6.2 to 6.6.124, 6.7 to 6.12.70, 6.13 to 6.18.10, 6.19-rc1 to 6.19-rc8

Timeline

  • 2026-03-18: disclosed: CVE published
  • 2026-02-11: patched: Fix committed to stable kernel tree

References

Related threats