CVE-2026-23103

EUVD-2026-5439
In the Linux kernel, the following vulnerability has been resolved:

ipvlan: Make the addrs_lock be per port

Make the addrs_lock be per port, not per ipvlan dev.

Initial code seems to be written in the assumption,
that any address change must occur under RTNL.
But it is not so for the case of IPv6. So

1) Introduce per-port addrs_lock.

2) It was needed to fix places where it was forgotten
to take lock (ipvlan_open/ipvlan_close)

This appears to be a very minor problem though.
Since it's highly unlikely that ipvlan_add_addr() will
be called on 2 CPU simultaneously. But nevertheless,
this could cause:

1) False-negative of ipvlan_addr_busy(): one interface
iterated through all port->ipvlans + ipvlan->addrs
under some ipvlan spinlock, and another added IP
under its own lock. Though this is only possible
for IPv6, since looks like only ipvlan_addr6_event() can be
called without rtnl_lock.

2) Race since ipvlan_ht_addr_add(port) is called under
different ipvlan->addrs_lock locks

This should not affect performance, since add/remove IP
is a rare situation and spinlock is not taken on fast
paths.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
4.17 ≤
𝑥
< 5.10.249
linuxlinux_kernel
5.11 ≤
𝑥
< 5.15.199
linuxlinux_kernel
5.16 ≤
𝑥
< 6.1.162
linuxlinux_kernel
6.2 ≤
𝑥
< 6.6.122
linuxlinux_kernel
6.7 ≤
𝑥
< 6.12.68
linuxlinux_kernel
6.13 ≤
𝑥
< 6.18.8
linuxlinux_kernel
6.19:rc1
linuxlinux_kernel
6.19:rc2
linuxlinux_kernel
6.19:rc3
linuxlinux_kernel
6.19:rc4
linuxlinux_kernel
6.19:rc5
linuxlinux_kernel
6.19:rc6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.170-3
fixed
bookworm (security)
6.1.172-1
fixed
bullseye
vulnerable
bullseye (security)
5.10.251-5
fixed
forky
7.0.7-1
fixed
sid
7.0.7-1
fixed
trixie
6.12.86-1
fixed
trixie (security)
6.12.88-1
fixed
linux-6.1
bullseye (security)
6.1.172-1~deb11u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cluster-md-kmp-default
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
dlm-kmp-default
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
gfs2-kmp-default
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
kernel-64kb
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1
fixed
kernel-default
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1
fixed
kernel-default-base
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1.150700.17.25.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1.150700.17.25.1
fixed
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1.150400.24.102.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1.150500.6.71.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1.150600.12.44.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1.150700.17.25.1
fixed
kernel-default-man
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
kernel-docs
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1
fixed
kernel-macros
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1
fixed
kernel-obs-build
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1
fixed
kernel-source
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1
fixed
kernel-syms
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1
fixed
kernel-zfcpdump
suse enterprise desktop 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.37.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.37.1
fixed
ocfs2-kmp-default
suse enterprise server 12 SP5
4.12.14-122.299.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed
reiserfs-kmp-default
suse enterprise server 15 SP4
5.14.21-150400.24.200.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.144.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.95.1
fixed