#VU124912 Memory corruption in Linux kernel - CVE-2026-23459
Published: April 6, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to memory corruption in iptunnel_xmit_stats() when updating tunnel transmit statistics for vxlan or geneve traffic. A local attacker can trigger the vulnerable code path to cause a denial of service.
On 32-bit kernels, overwriting the syncp sequence could lead to corruption or system freezes.