PT-2026-8166 · Linux · Linux Kernel

Published

2026-01-01

·

Updated

2026-04-25

·

CVE-2026-23171

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.19.0-rc6+
Description The Linux kernel contained a use-after-free flaw within the bonding driver. This issue occurs due to enslave failure after a new slave is added to the array. Specifically, the new slave can be used for transmission immediately, but it may be freed by the enslave error cleanup path, leading to a use-after-free condition. The problem is easily reproducible with a simple xdp pass program and parallel execution of commands. The crash involves a general protection fault and KASAN detection of a wild-memory-access. The vulnerability is located in the bond start xmit() function within the bonding module and netdev core pick tx function.
Recommendations Update to a version newer than 6.19.0-rc6+.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2026:6153
ALSA-2026:6632
AZL-77778
CVE-2026-23171
ECHO-26AB-7538-B6C0
OESA-2026-1863
OESA-2026-2076
OESA-2026-2077
OPENSUSE-SU-2026:20416-1
RHSA-2026:10108
RHSA-2026:6153
RHSA-2026:6632
RHSA-2026:8342
RHSA-2026:9112
RHSA-2026:9512
RHSA-2026:9644
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1

Affected Products

Linux Kernel