CVE-2026-23451

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. Add new "const struct net_device *dev" parameter to (struct header_ops)->parse() method to make sure the recursion is bounded, and that the final leaf parse method is called.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:6.12.78:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.18.19:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19.9:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

History

21 May 2026, 00:30

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/4172a7901cf43fe1cc63ef7a2ef33735ff7b7d13 - () https://git.kernel.org/stable/c/4172a7901cf43fe1cc63ef7a2ef33735ff7b7d13 - Patch
References () https://git.kernel.org/stable/c/946bb6cacf0ccada7bc80f1cfa07c1ed79511c1c - () https://git.kernel.org/stable/c/946bb6cacf0ccada7bc80f1cfa07c1ed79511c1c - Patch
References () https://git.kernel.org/stable/c/9b49c854f14f5e2d493e562a1e28d2e57fe37371 - () https://git.kernel.org/stable/c/9b49c854f14f5e2d493e562a1e28d2e57fe37371 - Patch
References () https://git.kernel.org/stable/c/b7405dcf7385445e10821777143f18c3ce20fa04 - () https://git.kernel.org/stable/c/b7405dcf7385445e10821777143f18c3ce20fa04 - Patch
CWE CWE-835
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12.78:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.18.19:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19.9:*:*:*:*:*:*:*

27 Apr 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-05-21 00:30


NVD link : CVE-2026-23451

Mitre link : CVE-2026-23451

CVE.ORG link : CVE-2026-23451


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')