CVE-2026-23083
HIGHLinux Kernel - Denial of Service via FOU_ATTR_IPPROTO Zero Value
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: fou: Don't allow 0 for FOU_ATTR_IPPROTO. fou_udp_recv() has the same problem mentioned in the previous patch. If FOU_ATTR_IPPROTO is set to 0, skb is not freed by fou_udp_recv() nor "resubmit"-ted in ip_protocol_deliver_rcu(). Let's forbid 0 for FOU_ATTR_IPPROTO.
References (7)
Core 7
Core References
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
4.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (24)
linux/Kernel
3.18.0 - 5.10.249linux
linux/Kernel
5.11.0 - 5.15.199linux
linux/Kernel
5.16.0 - 6.1.162linux
linux/Kernel
6.13.0 - 6.18.8linux
linux/Kernel
6.2.0 - 6.6.122linux
linux/Kernel
6.7.0 - 6.12.68linux
Linux/Linux
< 3.18
Linux/Linux
23461551c00628c3f3fe9cf837bf53cf8f212b63 - 1cc98b8887cabb1808d2f4a37cd10a7be7574771
Linux/Linux
23461551c00628c3f3fe9cf837bf53cf8f212b63 - 611ef4bd9c73d9e6d87bed57a635ff1fdd8c91ea
Linux/Linux
23461551c00628c3f3fe9cf837bf53cf8f212b63 - 6e983789b7588ee59cbf303583546c043bad8e19
... and 14 more
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026