PT-2026-8212 · Linux+3 · Linux Kernel+3
Gangmin Kim
·
Published
2026-01-01
·
Updated
2026-05-22
·
CVE-2026-23204
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains an issue within the networking scheduler (
cls u32) where the skb header pointer() function does not fully validate negative offset values. This can lead to out-of-bounds access. The recommended solution is to utilize skb header pointer careful() instead. A report and reproduction case were provided by GangMin Kim demonstrating a kernel slab out-of-bounds condition in the u32 classify() function.Recommendations
Utilize
skb header pointer careful() instead of skb header pointer().Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Rocky Linux
Ubuntu