CVE-2026-23083

HIGH

Linux Kernel - Denial of Service via FOU_ATTR_IPPROTO Zero Value

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: fou: Don't allow 0 for FOU_ATTR_IPPROTO. fou_udp_recv() has the same problem mentioned in the previous patch. If FOU_ATTR_IPPROTO is set to 0, skb is not freed by fou_udp_recv() nor "resubmit"-ted in ip_protocol_deliver_rcu(). Let's forbid 0 for FOU_ATTR_IPPROTO.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 4.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (24)
linux/Kernel 3.18.0 - 5.10.249linux
linux/Kernel 5.11.0 - 5.15.199linux
linux/Kernel 5.16.0 - 6.1.162linux
linux/Kernel 6.13.0 - 6.18.8linux
linux/Kernel 6.2.0 - 6.6.122linux
linux/Kernel 6.7.0 - 6.12.68linux
Linux/Linux < 3.18
Linux/Linux 23461551c00628c3f3fe9cf837bf53cf8f212b63 - 1cc98b8887cabb1808d2f4a37cd10a7be7574771
Linux/Linux 23461551c00628c3f3fe9cf837bf53cf8f212b63 - 611ef4bd9c73d9e6d87bed57a635ff1fdd8c91ea
Linux/Linux 23461551c00628c3f3fe9cf837bf53cf8f212b63 - 6e983789b7588ee59cbf303583546c043bad8e19
... and 14 more
Published Feb 04, 2026
Tracked Since Feb 18, 2026