CVE-2026-23319: bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
Published Mar 25, 2026
·Updated
bpf: Fix a UAF issue in bpftrampolinelinkcgroupshim
Affected Software
15 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.126.1-1
Linux Linux kernel>=6.0.1<6.1.167
Linux Linux kernel>=6.2<6.6.130
Linux Linux kernel>=6.7<6.12.77
Linux Linux kernel>=6.13<6.18.17
Linux Linux kernel>=6.19<6.19.7
Linux Linux kernel=6.0
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
Event History
Mar 25, 2026
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
Description
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 26, 2026
Data Sourced
via Microsoft·08:05 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:05 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-23319?
CVE-2026-23319 is classified as a high severity vulnerability due to the potential for exploitation leading to unauthorized access or denial of service.
2
How do I fix CVE-2026-23319?
To remediate CVE-2026-23319, users should apply the latest patches or updates provided for their Linux kernel version.
3
What are the potential impacts of CVE-2026-23319?
CVE-2026-23319 could lead to a use-after-free scenario, possibly allowing attackers to execute arbitrary code or crash affected systems.
4
Which versions of the Linux kernel are affected by CVE-2026-23319?
CVE-2026-23319 affects multiple versions of the Linux kernel, particularly those prior to the patches addressing the issue.
5
Is there a workaround for CVE-2026-23319?
While applying updates is the best practice, temporarily disabling BPF trampoline features may serve as a workaround until a patch can be applied.