CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()
dst: fix races in rt6uncachedlistdel() and rtdeluncachedlist()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply the IPv6 fix described: in rt6_uncached_list_del() (net/ipv6/route.c), add the missing locking so the function always grabs the spinlock before calling list_del_init()/INIT_LIST_HEAD on rt->dst.rt_uncached_list (i.e., avoid the race where list->next is written but list is freed before list->prev is updated).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23004?
CVE-2026-23004 has a high severity due to the potential for kernel crashes.
How do I fix CVE-2026-23004?
To fix CVE-2026-23004, you should update the Linux kernel to the latest patched version that resolves this vulnerability.
What are the potential impacts of CVE-2026-23004?
The impacts of CVE-2026-23004 include system instability and unexpected crashes, which could lead to denial of service.
Which versions of the Linux kernel are affected by CVE-2026-23004?
CVE-2026-23004 affects multiple versions of the Linux kernel prior to the fix being applied.
How can I determine if my system is vulnerable to CVE-2026-23004?
You can determine if your system is vulnerable to CVE-2026-23004 by checking the kernel version against the released patches for this CVE.