CVE-2026-23262
In the Linux kernel, the following vulnerability has been resolved:
gve: Fix stats report corruption on queue count change
The driver and the NIC share a region in memory for stats reporting. The NIC calculates its offset into this region based on the total size of the stats region and the size of the NIC's stats.
When the number of queues is changed, the driver's stats region is resized. If the queue count is increased, the NIC can write past the end of the allocated stats region, causing memory corruption. If the queue count is decreased, there is a gap between the driver and NIC stats, leading to incorrect stats reporting.
Leer descripción completaMostrar menos
This change fixes the issue by allocating stats region with maximum size, and the offset calculation for NIC stats is changed to match with the calculation of the NIC.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1565.001Stored Data Manipulationimpact80 % - Impacto secundario
T1499.004Application or System Exploitationimpact65 %
Vulnerabilidad de corrupción de memoria (CWE-787, buffer overflow) en kernel Linux con acceso local sin privilegios requeridos (AV:L, PR:L), permitiendo corrupción de datos compartidos entre driver y NIC, y potencial DoS.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-787
Referencias
- https://git.kernel.org/stable/c/11f8311f69e4c361717371b4901ff92daeb76e9c
- https://git.kernel.org/stable/c/7b9ebcce0296e104a0d82a6b09d68564806158ff
- https://git.kernel.org/stable/c/837c662f47dac43efa1aef2dd433c6b4b4c073af
- https://git.kernel.org/stable/c/9d93332397405b62a3300b22d04ac65d990b91ff
- https://git.kernel.org/stable/c/9fa0a755db3e1945fe00f73fe27d85ef6c8818b7
- https://git.kernel.org/stable/c/df54838ab61826ecc1a562ffa5e280c3ab7289a7
- https://git.kernel.org/stable/c/f432f7613c220db32c2c6942420daf7b3f2e7d7e
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23262",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c",
"lessThan": "f432f7613c220db32c2c6942420daf7b3f2e7d7e",
"versionType": "git"
},
{
"status": "affected",
"version": "24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c",
"lessThan": "9d93332397405b62a3300b22d04ac65d990b91ff",
"versionType": "git"
},
{
"status": "affected",
"version": "24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c",
"lessThan": "837c662f47dac43efa1aef2dd433c6b4b4c073af",
"versionType": "git"
},
{
"status": "affected",
"version": "24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c",
"lessThan": "df54838ab61826ecc1a562ffa5e280c3ab7289a7",
"versionType": "git"
},
{
"status": "affected",
"version": "24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c",
"lessThan": "9fa0a755db3e1945fe00f73fe27d85ef6c8818b7",
"versionType": "git"
},
{
"status": "affected",
"version": "24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c",
"lessThan": "11f8311f69e4c361717371b4901ff92daeb76e9c",
"versionType": "git"
},
{
"status": "affected",
"version": "24aeb56f2d38edf1b324bdb4f8bc6faf9f0f540c",
"lessThan": "7b9ebcce0296e104a0d82a6b09d68564806158ff",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/ethernet/google/gve/gve_ethtool.c",
"drivers/net/ethernet/google/gve/gve_main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.250",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.200",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.163",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.124",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.70",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.10",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/google/gve/gve_ethtool.c",
"drivers/net/ethernet/google/gve/gve_main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-03-18T18:16:24.770",
"references": [
{
"url": "https://git.kernel.org/stable/c/11f8311f69e4c361717371b4901ff92daeb76e9c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7b9ebcce0296e104a0d82a6b09d68564806158ff",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/837c662f47dac43efa1aef2dd433c6b4b4c073af",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9d93332397405b62a3300b22d04ac65d990b91ff",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9fa0a755db3e1945fe00f73fe27d85ef6c8818b7",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/df54838ab61826ecc1a562ffa5e280c3ab7289a7",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f432f7613c220db32c2c6942420daf7b3f2e7d7e",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngve: Fix stats report corruption on queue count change\n\nThe driver and the NIC share a region in memory for stats reporting.\nThe NIC calculates its offset into this region based on the total size\nof the stats region and the size of the NIC's stats.\n\nWhen the number of queues is changed, the driver's stats region is\nresized. If the queue count is increased, the NIC can write past\nthe end of the allocated stats region, causing memory corruption.\nIf the queue count is decreased, there is a gap between the driver\nand NIC stats, leading to incorrect stats reporting.\n\nThis change fixes the issue by allocating stats region with maximum\nsize, and the offset calculation for NIC stats is changed to match\nwith the calculation of the NIC."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\ngve: Corrección de la corrupción del informe de estadísticas al cambiar el recuento de colas\n\nEl controlador y la NIC comparten una región en memoria para el informe de estadísticas.\nLa NIC calcula su desplazamiento en esta región basándose en el tamaño total\nde la región de estadísticas y el tamaño de las estadísticas de la NIC.\n\nCuando se cambia el número de colas, la región de estadísticas del controlador se\nredimensiona. Si el recuento de colas se incrementa, la NIC puede escribir más allá\ndel final de la región de estadísticas asignada, causando corrupción de memoria.\nSi el recuento de colas se disminuye, hay una brecha entre las estadísticas del controlador\ny de la NIC, lo que lleva a un informe de estadísticas incorrecto.\n\nEste cambio soluciona el problema asignando la región de estadísticas con el tamaño\nmáximo, y el cálculo del desplazamiento para las estadísticas de la NIC se cambia para que\ncoincida con el cálculo de la NIC."
}
],
"lastModified": "2026-06-17T10:21:12.570",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87E8A246-2D3F-4484-80EA-D00ED138130E",
"versionEndExcluding": "5.10.250",
"versionStartIncluding": "5.10"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D16F6370-B70F-471C-8363-3A17B0BB1DA9",
"versionEndExcluding": "5.15.200",
"versionStartIncluding": "5.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9C856E1-4308-4C0B-A973-7DD375DF66C4",
"versionEndExcluding": "6.1.163",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76183B9F-CABE-4E21-A3E3-F0EBF99DC3C7",
"versionEndExcluding": "6.6.124",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3791390-0628-4808-99EF-1ED8ABF60933",
"versionEndExcluding": "6.12.70",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7156C23F-009E-4D05-838C-A2DA417B5B8D",
"versionEndExcluding": "6.18.10",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17B67AA7-40D6-4AFA-8459-F200F3D7CFD1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C47E4CC9-C826-4FA9-B014-7FE3D9B318B2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F71D92C0-C023-48BD-B3B6-70B638EEE298"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13580667-0A98-40CC-B29F-D12790B91BDB"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAD1FED7-CF48-47BF-AC7D-7B6FA3C065FC"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EF854A1-ABB1-4E93-BE9A-44569EC76C0D"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5DC0CA6-F0AF-4DDF-A882-3DADB9A886A7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB5B7DFC-C36B-45D8-922C-877569FDDF43"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}