CVE-2026-23451

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. Add new "const struct net_device *dev" parameter to (struct header_ops)->parse() method to make sure the recursion is bounded, and that the final leaf parse method is called.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:6.12.78:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.18.19:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-23451

Mitre link : CVE-2026-23451

CVE.ORG link : CVE-2026-23451


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')