CVE-2026-23302: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: annotate data-races around sk->sk_{data_ready,write_space} skmsg (and probably other layers) are changing these pointers while other cpus might read them concurrently. Add corresponding READ_ONCE()/WRITE_ONCE() annotations for UDP, TCP and AF_UNIX.

Affected products

  • Linux Linux Kernel: from 4.20, before 6.6.136 (fixed in 6.6.136); from 6.7, before 6.12.82 (fixed in 6.12.82); from 6.13, before 6.18.17 (fixed in 6.18.17); from 6.19, before 6.19.7 (fixed in 6.19.7); version 7.0 only

Published 2026-03-25. Last modified 2026-07-04.