LiveActive security incident?Get immediate response
CVE Record

CVE-2026-23119: bonding: provide a net pointer to __skb_flow_dissect()

In the Linux kernel, the following vulnerability has been resolved: bonding: provide a net pointer to __skb_flow_dissect() After 3cbf4ffba5ee ("net: plumb network namespace into __skb_flow_dissect") we have to provide a net pointer to __skb_flow_dissect(), either via skb->dev, skb->sk, or a user provided pointer. In the following case, syzbot was able to cook a bare skb. WARNING: net/core/flow_dissector.c:1131 at __skb_flow_dissect+0xb57/0x68b0 net/core/flow_dissector.c:1131, CPU#1: syz.2.1418/11053 Call Trace: <TASK> bond_flow_dissect drivers/net/bonding/bond_main.c:4093 [inline] __bond_xmit_hash+0x2d7/0xba0 drivers/net/bonding/bond_main.c:4157 bond_xmit_hash_xdp drivers/net/bonding/bond_main.c:4208 [inline] bond_xdp_xmit_3ad_xor_slave_get drivers/net/bonding/bond_main.c:5139 [inline] bond_xdp_get_xmit_slave+0x1fd/0x710 drivers/net/bonding/bond_main.c:5515 xdp_master_redirect+0x13f/0x2c0 net/core/filter.c:4388 bpf_prog_run_xdp include/net/xdp.h:700 [inline] bpf_test_run+0x6b2/0x7d0 net/bpf/test_run.c:421 bpf_prog_test_run_xdp+0x795/0x10e0 net/bpf/test_run.c:1390 bpf_prog_test_run+0x2c7/0x340 kernel/bpf/syscall.c:4703 __sys_bpf+0x562/0x860 kernel/bpf/syscall.c:6182 __do_sys_bpf kernel/bpf/syscall.c:6274 [inline] __se_sys_bpf kernel/bpf/syscall.c:6272 [inline] __x64_sys_bpf+0x7c/0x90 kernel/bpf/syscall.c:6272 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xec/0xf80 arch/x86/entry/syscall_64.c:94

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel bonding-networking flaw found by syzbot. A crafted kernel packet path could trigger a kernel warning because bonding called the flow dissector without required network namespace context. The public record does not provide CVSS, impact details, or evidence of active exploitation.

Executive priority

Treat as a kernel maintenance item with unclear business impact. Prioritize patching network infrastructure and hosts using bonding or advanced packet processing, but do not classify as emergency without additional vendor severity or exploitation evidence.

Technical view

The issue is in Linux bonding transmit hashing for XDP paths. After network namespace plumbing changed __skb_flow_dissect(), bonding needed to pass a net pointer. The provided trace reaches bond_flow_dissect through bpf_prog_test_run_xdp and __sys_bpf. Kernel stable commits are listed as the resolution references.

Likely exposure

Exposure appears limited to Linux systems running affected kernel builds with bonding code reachable, especially where XDP/BPF test or redirect paths are available. The source data does not identify distributions, appliances, or cloud images by name.

Exploitation context

No KEV listing is provided, and the bundle contains no cited report of exploitation in the wild. The evidence is a syzbot-generated kernel warning and upstream stable fixes, not a public exploit report.

Researcher notes

The available record shows a missing net pointer to __skb_flow_dissect() in bonding after commit 3cbf4ffba5ee changed flow dissector context handling. The trace suggests a BPF/XDP test path can construct the triggering skb. Impact beyond warning is not established in the bundle.

Mitigation direction

  • Update to a vendor kernel containing the referenced stable fixes.
  • Prioritize systems using Linux bonding, XDP, or BPF-heavy networking.
  • Check distribution advisories for backported fixes before relying on version numbers.
  • Avoid treating untrusted BPF/XDP access as broadly safe until patched.

Validation and detection

  • Identify running kernel versions across Linux fleets.
  • Check whether bonding interfaces or bonding modules are enabled.
  • Review whether BPF program test or XDP functionality is available to users.
  • Compare vendor kernel packages against the listed upstream stable commits.
  • Track CVE Program updates for CVSS, CWE, or impact clarification.
Prepared
Confidence
medium
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2026-23119 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
1ADP providers
8Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux58deb77cc52da9360d20676e68dd215742cbe473, 58deb77cc52da9360d20676e68dd215742cbe473, 58deb77cc52da9360d20676e68dd215742cbe473, 58deb77cc52da9360d20676e68dd215742cbe473, 58deb77cc52da9360d20676e68dd215742cbe473, 58deb77cc52da9360d20676e68dd215742cbe473, 58deb77cc52da9360d20676e68dd215742cbe473unaffected
LinuxLinux5.5, 0, 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.68, 6.18.8, 6.19affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.