Junglewise Threat Intelligence

CVE-2026-23273: Linux kernel use-after-free in macvlan_common_newlink

CVE-2026-23273 · Severity: high · CVSS 7.8 · Published 2026-03-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system or potentially gain unauthorized access to data. The issue occurs when the system incorrectly handles errors while creating virtual network interfaces (macvlan), leading to a memory safety error. This could disrupt network operations or be used as a stepping stone for further attacks on the host system.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel macvlan driver. The root cause is a race condition in macvlan_common_newlink() where a network device (@dev) may be made visible to the system before an error is detected. If an error occurs subsequently, the caller (rtnl_newlink) immediately frees the device without waiting for an RCU grace period. This allows other parts of the networking stack, such as macvlan_forward_source(), to access the memory after it has been freed. An attacker with local access can trigger this by attempting to create a macvlan interface with invalid parameters while simultaneously generating network traffic. The fix involves adding synchronize_net() to the error path to ensure RCU grace periods are observed before memory reclamation.

Affected products

  • Linux Linux kernel 5.10.250 to 5.10.252, 5.15.200 to 5.15.202, 6.1.163 to 6.1.165, 6.6.124 to 6.6.128, 6.12.70 to 6.12.75, 6.18.10 to 6.18.14, 6.19.1 to 6.19.4

Timeline

  • 2026-02-13: patched: Initial patch authored by Eric Dumazet
  • 2026-03-20: advisory: CVE-2026-23273 published

References