Junglewise Threat Intelligence

CVE-2026-23453: Linux Kernel TI ICSSG PRU Ethernet memory leak in XDP_DROP

CVE-2026-23453 · Severity: high · CVSS 7.5 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Texas Instruments (TI) network driver for the Linux kernel can cause a system to run out of memory. This occurs when the system processes specific types of network traffic using high-performance packet processing (XDP). If exploited, this could lead to a complete system crash or service outage, impacting business operations and network availability.

Technical details

A memory leak (CWE-401) exists in the Texas Instruments ICSSG PRU Ethernet driver (icssg-prueth) within the Linux kernel. The vulnerability is located in the emac_run_xdp() function, where page recycling was incorrectly removed from the XDP_DROP path to avoid conflicts with AF_XDP zero-copy mode. In standard page pool (non-zero-copy) mode, pages are never returned to the pool when a packet is dropped, eventually leading to an Out-of-Memory (OOM) state. An attacker can trigger this by sending network traffic that causes an XDP program to execute the XDP_DROP action. The issue has been resolved by ensuring emac_rx_packet() correctly recycles pages when ICSSG_XDP_CONSUMED is returned.

Affected products

  • Linux Linux Kernel 6.19 to 6.19.10, 7.0-rc1 to 7.0-rc4

Timeline

  • 2026-03-11: other: Patch authored by TI developer
  • 2026-04-03: advisory: CVE published by kernel.org
  • 2026-05-26: other: NVD initial analysis completed

References

Related threats