CVE-2026-23331 addresses a bug in the Linux kernel's UDP networking stack concerning how auto-bound, connected sockets are handled in the 4-tuple hash table upon disconnection, potentially leaving "garbage" entries. This vulnerability affects the Linux kernel. The severity appears low, with no CVSS score, a very low EPSS (0.00017), and a low FAUCET Risk Score (20.0/100), suggesting a minor impact. There is no indication of active exploitation, public exploit code, or significant community attention, with only minimal mentions and articles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.13.1, < 6.18.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.19, < 6.19.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.13:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.