CVE-2026-23359Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack-out-of-bounds write in devmap get_upper_ifindexes() iterates over all upper devices and writes their indices into an array without checking bounds. Also the callers assume that the max number of upper devices is MAX_NEST_DEV and allocate excluded_devices[1+MAX_NEST_DEV] on the stack, but that assumption is not correct and the number of upper devices could be larger than MAX_NEST_DEV (e.g., many macvlans), causing a stack-out-of-bounds write. Add a max parameter to get_upper_ifindexes() to avoid the issue. When there are too many upper devices, return -EOVERFLOW and abort the redirect. To reproduce, create more than MAX_NEST_DEV(8) macvlans on a device with an XDP program attached using BPF_F_BROADCAST | BPF_F_EXCLUDE_INGRESS. Then send a packet to the device to trigger the XDP redirect path.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-26); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-25: 1Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Mentions · 2026-04-26: 1PoC Mentioned / Linked · 2026-04-26: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-26: 103-2503-2603-2704-26
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-262
Disclosure2
2026-03-271
Disclosure1
2026-04-261
PoC1
Full discourse5 posts
  • OverResearched Intelligence@ORIntelligence
    PoC

    🔴 CVE-2026-3844 Breeze Cache RCE — PoC live 🔴 CVE-2026-23359 Linux BPF OOB write 🟠 Qilin/Lockbit5/M3rx: 16 victims 🟠 Itron utility 8-K breach Full brief: https://intel.overresearched.net/2026/04/26/cti-daily-brief/ #Daily #ThreatIntel #InfoSec

    Post summary

    The brief announces a live PoC for the Breeze Cache RCE (CVE-2026-3844) and references another CVE, while also listing unrelated attack incidents, but provides no mitigation or exploitation claims.

    00000157
    4 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-23359 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23359 #CVE-2026-23359 #CVE   #CyberSecurity #InfoSec https://t.co/JBoNW2ZV9f

    Post summary

    The tweet announces the existence of CVE-2026-23359 with basic metadata but lacks any information on exploitation, patching, or technical specifics.

    0000033
    123 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    😬 This isn’t “just Linux,” it’s a reminder that one missed bounds check turns networking into a crash roulette. Security matters—doesn’t matter the OS, only the bug. https://windowsforum.com/threads/cve-2026-23359-linux-kernel-bpf-devmap-stack-overflow-in-xdp-redirect.407468/ #LinuxKernel #BpfDevmap #Cve202623359 #XdpRedirect https://t.co/DK9bSxEvOA

    Post summary

    The tweet highlights a Linux kernel BPF devmap stack‑overflow vulnerability (CVE‑2026‑23359) that can crash networking services via an XDP redirect bounds check failure; it lacks evidence of exploitation, a PoC, or a fix.

    0000030
    1.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Linux Kernel (CVE-2026-23359) https://vuldb.com/?id.353093

    Post summary

    A severe Linux kernel vulnerability (CVE-2026-23359) has been disclosed, with a link to a vulnerability database for further details.

    0000063
    2.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23359 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack-out-of-bounds write in devmap get_upper_ifindexes() iterates over all upper devic… https://www.cve.org/CVERecord?id=CVE-2026-23359

    Post summary

    The note announces that CVE‑2026‑23359, a stack‑out‑of‑bounds flaw in Linux kernel BPF devmap, has been fixed, but no PoC, exploit, or active usage is mentioned.

    00000112
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.15--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more