CVE-2026-23124 addresses a data-race vulnerability in the Linux kernel's IPv6 networking stack, specifically within the ndisc_router_discovery() function. This race condition occurs when reading and writing the in6_dev->ra_mtu value without proper locking mechanisms. While the immediate impact is considered "best effort" and not critical, it indicates an underlying concurrency issue. The vulnerability has no assigned CVSS score, and its EPSS and FAUCET Risk Scores are very low, suggesting a minimal security risk. The attack vector and complexity are not explicitly detailed but appear to be internal to the kernel's operation, with no immediate indication of direct external exploitability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. This indicates a low level of attention and perceived threat from the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.15, < 5.15.199CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.162CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.122CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.68CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.18.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel (OEM) vulnerabilities
Jul 23, 2026Linux kernel vulnerabilities
Jul 20, 2026Linux kernel (Xilinx) vulnerabilities
Jul 2, 2026Linux kernel (Azure) vulnerabilities
May 26, 2026Linux kernel (NVIDIA) vulnerabilities
May 25, 2026Linux kernel (NVIDIA Tegra) vulnerabilities
May 25, 2026Linux kernel (NVIDIA) vulnerabilities
May 20, 2026Linux kernel vulnerabilities
May 19, 2026Linux kernel (Xilinx ZynqMP) vulnerabilities
May 19, 2026Linux kernel (Raspberry Pi) vulnerabilities
May 11, 2026Linux kernel (Azure) vulnerabilities
May 7, 2026Linux kernel (IBM) vulnerabilities
Apr 24, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 23, 2026Linux kernel vulnerabilities
Apr 23, 2026Linux kernel (HWE) vulnerabilities
Apr 17, 2026Linux kernel (NVIDIA) vulnerabilities
Apr 17, 2026Linux kernel (Real-time) vulnerabilities
Apr 17, 2026Linux kernel (FIPS) vulnerabilities
Apr 17, 2026Linux kernel vulnerabilities
Apr 16, 2026Linux kernel (NVIDIA Tegra) vulnerabilities
Apr 9, 2026kernel: Linux kernel: Data race in IPv6 neighbor discovery leads to limited availability
Feb 14, 2026