« Volver al listado

CVE-2026-23451

Estado: ModificadaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

bonding: prevent potential infinite loop in bond_header_parse()

bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top.

Add new "const struct net_device *dev" parameter to (struct header_ops)->parse() method to make sure the recursion is bounded, and that the final leaf parse method is called.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N sin autenticación sugiere exposición remota (T1190), pero es bucle infinito por diseño (no clásico). Impacto principal DoS por agotamiento de recursos (CWE-835, infinite loop → T1499.004). Escalada potencial si kernel crash.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-23451",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5d0fb9806ab6cf2c3cfba0e1b8c701da65e25af8",
              "lessThan": "9532d0d0ad1d726c06f807e8f0f1ec93cbabb452",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9baf26a91565b7bb2b1d9f99aaf884a2b28c2f6d",
              "lessThan": "946bb6cacf0ccada7bc80f1cfa07c1ed79511c1c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6ac890f1d60ac3707ee8dae15a67d9a833e49956",
              "lessThan": "4172a7901cf43fe1cc63ef7a2ef33735ff7b7d13",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "95597d11dc8bddb2b9a051c9232000bfbb5e43ba",
              "lessThan": "9b49c854f14f5e2d493e562a1e28d2e57fe37371",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "950803f7254721c1c15858fbbfae3deaaeeecb11",
              "lessThan": "b7405dcf7385445e10821777143f18c3ce20fa04",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/firewire/net.c",
            "drivers/net/bonding/bond_main.c",
            "include/linux/etherdevice.h",
            "include/linux/if_ether.h",
            "include/linux/netdevice.h",
            "net/ethernet/eth.c",
            "net/ipv4/ip_gre.c",
            "net/mac802154/iface.c",
            "net/phonet/af_phonet.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18.19",
              "lessThan": "6.18.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.9",
              "lessThan": "6.19.10",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/firewire/net.c",
            "drivers/net/bonding/bond_main.c",
            "include/linux/etherdevice.h",
            "include/linux/if_ether.h",
            "include/linux/netdevice.h",
            "net/ethernet/eth.c",
            "net/ipv4/ip_gre.c",
            "net/mac802154/iface.c",
            "net/phonet/af_phonet.c"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-03T16:16:31.460",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4172a7901cf43fe1cc63ef7a2ef33735ff7b7d13",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/946bb6cacf0ccada7bc80f1cfa07c1ed79511c1c",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9532d0d0ad1d726c06f807e8f0f1ec93cbabb452",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b49c854f14f5e2d493e562a1e28d2e57fe37371",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7405dcf7385445e10821777143f18c3ce20fa04",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-835"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: prevent potential infinite loop in bond_header_parse()\n\nbond_header_parse() can loop if a stack of two bonding devices is setup,\nbecause skb->dev always points to the hierarchy top.\n\nAdd new \"const struct net_device *dev\" parameter to\n(struct header_ops)->parse() method to make sure the recursion\nis bounded, and that the final leaf parse method is called."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nbonding: prevenir un potencial bucle infinito en bond_header_parse()\n\nbond_header_parse() puede entrar en bucle si se configura una pila de dos dispositivos bonding, porque skb  ->  dev siempre apunta a la cima de la jerarquía.\n\nAñadir un nuevo parámetro 'const struct net_device dev' al método (struct header_ops)  ->  parse() para asegurar que la recursión esté acotada y que se llame al método de análisis de hoja final."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.12.78:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "493FF782-C903-4656-94E0-20B2D0EA024C"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.18.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D24CF0E-E6F3-40B8-97C7-4913453B199F"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB047D77-F8E9-431C-8103-B177734E5125"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02259FDA-961B-47BC-AE7F-93D7EC6E90C2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}