CVE-2026-23273: macvlan: observe an RCU grace period in macvlan_common_newlink() error path
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1Fixed in 7.0.12-2 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.174-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23273?
CVE-2026-23273 has been assigned a severity level that indicates a significant potential for exploitation due to the race condition in the macvlan functionality.
How do I fix CVE-2026-23273?
To fix CVE-2026-23273, update to the latest version of the Linux kernel where the vulnerability has been addressed.
What systems are affected by CVE-2026-23273?
CVE-2026-23273 affects systems running the Linux kernel with macvlan configured.
What is the nature of the vulnerability in CVE-2026-23273?
CVE-2026-23273 involves a race condition observed during the error path in the macvlan_common_newlink() function.
Is CVE-2026-23273 currently being exploited in the wild?
As of now, there is no public indication that CVE-2026-23273 is being actively exploited.