CVE-2026-23342 describes a race condition in the Linux kernel's BPF cpumap functionality, specifically impacting PREEMPT_RT kernels. This vulnerability arises because local_bh_disable() does not fully prevent preemption on PREEMPT_RT, allowing multiple tasks to concurrently access and corrupt per-CPU xdp_bulk_queue structures. Such concurrent access can lead to kernel crashes (oops) due to double free-like conditions or data corruption within the packet queue, potentially resulting in denial of service or system instability. While the FAUCET Risk Score is 20.0/100, there is no evidence of active exploitation, public exploit code, or significant community discussion, and its EPSS score is very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.18.1, < 6.18.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.19, < 6.19.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.18:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.