CVE-2026-23451: Linux Kernel
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. Add new "const struct net_device *dev" parameter to (struct header_ops)->parse() method to make sure the recursion is bounded, and that the final leaf parse method is called.
Affected products
- Linux Linux Kernel: version 6.12.78 only; version 6.18.19 only; version 6.19.9 only; version 7.0 only
Published 2026-04-03. Last modified 2026-07-24.