CVE-2026-23389: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice_set_ringparam, tx_rings and xdp_rings are allocated before rx_rings. If the allocation of rx_rings fails, the code jumps to the done label leaking both tx_rings and xdp_rings. Furthermore, if the setup of an individual Rx ring fails during the loop, the code jumps to the free_tx label which releases tx_rings but leaks xdp_rings. Fix this by introducing a free_xdp label and updating the error paths to ensure both xdp_rings and tx_rings are properly freed if rx_rings allocation or setup fails. Compile tested only. Issue found using a prototype static analysis tool and code review.

Affected products

  • Linux Linux Kernel: from 4.17.1, before 6.12.81 (fixed in 6.12.81); from 6.13, before 6.18.22 (fixed in 6.18.22); from 6.19, before 6.19.7 (fixed in 6.19.7); version 4.17 only; version 7.0 only

Published 2026-03-25. Last modified 2026-06-17.