Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to crash the system or potentially gain unauthorized access to data. The issue occurs when the system incorrectly handles errors while creating virtual network interfaces (macvlan), leading to a memory safety error. This could disrupt network operations or be used as a stepping stone for further attacks on the host system.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel macvlan driver. The root cause is a race condition in macvlan_common_newlink() where a network device (@dev) may be made visible to the system before an error is detected. If an error occurs subsequently, the caller (rtnl_newlink) immediately frees the device without waiting for an RCU grace period. This allows other parts of the networking stack, such as macvlan_forward_source(), to access the memory after it has been freed. An attacker with local access can trigger this by attempting to create a macvlan interface with invalid parameters while simultaneously generating network traffic. The fix involves adding synchronize_net() to the error path to ensure RCU grace periods are observed before memory reclamation.
Affected products
- Linux Linux kernel 5.10.250 to 5.10.252, 5.15.200 to 5.15.202, 6.1.163 to 6.1.165, 6.6.124 to 6.6.128, 6.12.70 to 6.12.75, 6.18.10 to 6.18.14, 6.19.1 to 6.19.4
Timeline
- 2026-02-13: patched: Initial patch authored by Eric Dumazet
- 2026-03-20: advisory: CVE-2026-23273 published
References
- https://git.kernel.org/stable/c/19c7d8ac51988d053709c1e85bd8482076af845d
- https://git.kernel.org/stable/c/1e58ae87ad1e6e24368dea9aec9048c758cd0e2b
- https://git.kernel.org/stable/c/3d94323c80d7fc4da5f10f9bb06a45d39d5d3cc4
- https://git.kernel.org/stable/c/721eb342d9ba19bad5c4815ea3921465158b7362
- https://git.kernel.org/stable/c/91e4ff8d966978901630fc29582c1a76d3c6e46c
- https://git.kernel.org/stable/c/a1f686d273d129b45712d95f4095843b864466bd
- https://git.kernel.org/stable/c/d34f7a8aa9a25b7e64e0e46e444697c0f702374d