Junglewise Threat Intelligence

CVE-2026-23343: Linux Kernel out-of-bounds write in XDP tailroom calculation

CVE-2026-23343 · Severity: high · CVSS 7.8 · Published 2026-03-25

Technologies: Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's networking component (XDP) that can lead to system instability or memory corruption. The issue occurs when certain network drivers incorrectly calculate the available space for incoming data, potentially allowing a local attacker to trigger a system crash or gain unauthorized access to memory. This affects systems using specific Ethernet drivers and high-performance networking features.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) caused by an integer underflow in the XDP component of the Linux kernel. Many Ethernet drivers (such as ixgbevf) report the Rx queue fragment size as the DMA write size rather than the actual truesize. When bpf_xdp_frags_increase_tail() is called, this discrepancy, combined with a non-zero page offset, results in a negative tailroom calculation. Because tailroom is stored as an unsigned integer, the negative value wraps to a large positive number (near UINT_MAX), causing the kernel to attempt to grow the packet tail beyond the physical buffer limits. This leads to memory corruption and kernel oops/general protection faults. Patches have been released in the stable kernel tree to validate tailroom calculations.

Affected products

  • Linux Linux Kernel 6.19.0-rc1+
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2026-03-05: patched: Initial patch authored by Larysa Zaremba
  • 2026-03-25: advisory: CVE published and NVD record created

References

Related threats