[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-23171":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T14:53:31.930Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":60,"related":61,"reserved_at":9,"published_at":73,"modified_at":74,"state":75,"summary":76,"references_raw":85,"kevs":104,"epss":105,"epss_history":108,"metrics":379,"affected":387},"CVE-2026-23171","In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix use-after-free due to enslave fail after slave array update\n\nFix a use-after-free which happens due to enslave failure after the new\nslave has been added to the array. Since the new slave can be used for Tx\nimmediately, we can use it after it has been freed by the enslave error\ncleanup path which frees the allocated slave memory. Slave update array is\nsupposed to be called last when further enslave failures are not expected.\nMove it after xdp setup to avoid any problems.\n\nIt is very easy to reproduce the problem with a simple xdp_pass prog:\n ip l add bond1 type bond mode balance-xor\n ip l set bond1 up\n ip l set dev bond1 xdp object xdp_pass.o sec xdp_pass\n ip l add dumdum type dummy\n\nThen run in parallel:\n while :; do ip l set dumdum master bond1 1>/dev/null 2>&1; done;\n mausezahn bond1 -a own -b rand -A rand -B 1.1.1.1 -c 0 -t tcp \"dp=1-1023, flags=syn\"\n\nThe crash happens almost immediately:\n [  605.602850] Oops: general protection fault, probably for non-canonical address 0xe0e6fc2460000137: 0000 [#1] SMP KASAN NOPTI\n [  605.602916] KASAN: maybe wild-memory-access in range [0x07380123000009b8-0x07380123000009bf]\n [  605.602946] CPU: 0 UID: 0 PID: 2445 Comm: mausezahn Kdump: loaded Tainted: G    B               6.19.0-rc6+ #21 PREEMPT(voluntary)\n [  605.602979] Tainted: [B]=BAD_PAGE\n [  605.602998] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n [  605.603032] RIP: 0010:netdev_core_pick_tx+0xcd/0x210\n [  605.603063] Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 3e 01 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b 6b 08 49 8d 7d 30 48 89 fa 48 c1 ea 03 \u003C80> 3c 02 00 0f 85 25 01 00 00 49 8b 45 30 4c 89 e2 48 89 ee 48 89\n [  605.603111] RSP: 0018:ffff88817b9af348 EFLAGS: 00010213\n [  605.603145] RAX: dffffc0000000000 RBX: ffff88817d28b420 RCX: 0000000000000000\n [  605.603172] RDX: 00e7002460000137 RSI: 0000000000000008 RDI: 07380123000009be\n [  605.603199] RBP: ffff88817b541a00 R08: 0000000000000001 R09: fffffbfff3ed8c0c\n [  605.603226] R10: ffffffff9f6c6067 R11: 0000000000000001 R12: 0000000000000000\n [  605.603253] R13: 073801230000098e R14: ffff88817d28b448 R15: ffff88817b541a84\n [  605.603286] FS:  00007f6570ef67c0(0000) GS:ffff888221dfa000(0000) knlGS:0000000000000000\n [  605.603319] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n [  605.603343] CR2: 00007f65712fae40 CR3: 000000011371b000 CR4: 0000000000350ef0\n [  605.603373] Call Trace:\n [  605.603392]  \u003CTASK>\n [  605.603410]  __dev_queue_xmit+0x448/0x32a0\n [  605.603434]  ? __pfx_vprintk_emit+0x10/0x10\n [  605.603461]  ? __pfx_vprintk_emit+0x10/0x10\n [  605.603484]  ? __pfx___dev_queue_xmit+0x10/0x10\n [  605.603507]  ? bond_start_xmit+0xbfb/0xc20 [bonding]\n [  605.603546]  ? _printk+0xcb/0x100\n [  605.603566]  ? __pfx__printk+0x10/0x10\n [  605.603589]  ? bond_start_xmit+0xbfb/0xc20 [bonding]\n [  605.603627]  ? add_taint+0x5e/0x70\n [  605.603648]  ? add_taint+0x2a/0x70\n [  605.603670]  ? end_report.cold+0x51/0x75\n [  605.603693]  ? bond_start_xmit+0xbfb/0xc20 [bonding]\n [  605.603731]  bond_start_xmit+0x623/0xc20 [bonding]",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58],{"_key":25},"SUSE-SU-2026:20667-1",{"_key":27},"SUSE-SU-2026:20720-1",{"_key":29},"SUSE-SU-2026:0962-1",{"_key":31},"SUSE-SU-2026:1081-1",{"_key":33},"SUSE-SU-2026:20838-1",{"_key":35},"SUSE-SU-2026:20845-1",{"_key":37},"OPENSUSE-SU-2026:20416-1",{"_key":39},"SUSE-SU-2026:20876-1",{"_key":41},"SUSE-SU-2026:20931-1",{"_key":43},"RHSA-2026:6153",{"_key":45},"RHSA-2026:6632",{"_key":47},"RHSA-2026:9112",{"_key":49},"DEBIAN-CVE-2026-23171",{"_key":51},"RHSA-2026:8342",{"_key":53},"RHSA-2026:10108",{"_key":55},"RHSA-2026:9512",{"_key":57},"RHSA-2026:9644",{"_key":59},"UBUNTU-CVE-2026-23171",[],[62,63,64,65,66,67,68,69,70,71],{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":72},"CGA-VVR9-4C3V-2FH5","2026-02-14T16:01:33.489Z","2026-05-17T15:21:17.241Z","Modified",{"cisa_kev":77,"cisa_ransomware":77,"cisa_vendor":9,"epss_severity":78,"epss_score":79,"severity":80,"severity_score":81,"severity_version":82,"severity_source":83,"severity_vector":84,"severity_status":75},false,"low",0.00018,"high",7.8,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",[86,92,96,100],{"url":87,"sources":88,"tags":90},"https://git.kernel.org/stable/c/bd25b092a06a3e05f7e8bd6da6fa7318777d8c3d",[89,83],"cve.org",[91],"Patch",{"url":93,"sources":94,"tags":95},"https://git.kernel.org/stable/c/e9acda52fd2ee0cdca332f996da7a95c5fd25294",[89,83],[91],{"url":97,"sources":98,"tags":99},"https://git.kernel.org/stable/c/172dcb67dd35b162357df229d7806acc724cd469",[89,83],[],{"url":101,"sources":102,"tags":103},"https://git.kernel.org/stable/c/2889d92c5f728351c9930c7996d22fe6e906e785",[89,83],[],[],{"date":106,"score":79,"percentile":107},"2026-06-04",0.04698,[109,112,115,118,121,124,128,131,134,137,140,143,146,149,152,155,158,161,164,167,170,173,176,179,182,185,187,190,193,196,199,202,206,210,213,216,219,222,225,228,231,234,237,240,243,245,248,251,254,257,260,263,266,269,272,275,278,281,284,287,290,293,296,298,301,304,307,310,314,317,320,323,326,329,332,335,338,341,344,347,349,352,355,358,361,364,367,370,373,376],{"date":110,"score":79,"percentile":111},"2026-02-15",0.04226,{"date":113,"score":79,"percentile":114},"2026-02-16",0.04221,{"date":116,"score":79,"percentile":117},"2026-02-17",0.04203,{"date":119,"score":79,"percentile":120},"2026-02-18",0.0447,{"date":122,"score":79,"percentile":123},"2026-02-19",0.04529,{"date":125,"score":126,"percentile":127},"2026-02-20",0.00024,0.06395,{"date":129,"score":126,"percentile":130},"2026-02-21",0.06413,{"date":132,"score":126,"percentile":133},"2026-02-22",0.06404,{"date":135,"score":126,"percentile":136},"2026-02-23",0.06409,{"date":138,"score":126,"percentile":139},"2026-02-24",0.064,{"date":141,"score":126,"percentile":142},"2026-02-25",0.06331,{"date":144,"score":126,"percentile":145},"2026-02-26",0.0628,{"date":147,"score":126,"percentile":148},"2026-02-27",0.06309,{"date":150,"score":126,"percentile":151},"2026-02-28",0.06311,{"date":153,"score":126,"percentile":154},"2026-03-01",0.0637,{"date":156,"score":126,"percentile":157},"2026-03-02",0.06316,{"date":159,"score":126,"percentile":160},"2026-03-03",0.06325,{"date":162,"score":126,"percentile":163},"2026-03-04",0.06237,{"date":165,"score":126,"percentile":166},"2026-03-05",0.0627,{"date":168,"score":126,"percentile":169},"2026-03-06",0.06254,{"date":171,"score":126,"percentile":172},"2026-03-07",0.06266,{"date":174,"score":126,"percentile":175},"2026-03-08",0.06226,{"date":177,"score":126,"percentile":178},"2026-03-09",0.06192,{"date":180,"score":126,"percentile":181},"2026-03-10",0.06189,{"date":183,"score":126,"percentile":184},"2026-03-11",0.06207,{"date":186,"score":126,"percentile":163},"2026-03-12",{"date":188,"score":126,"percentile":189},"2026-03-13",0.06258,{"date":191,"score":126,"percentile":192},"2026-03-14",0.06215,{"date":194,"score":126,"percentile":195},"2026-03-15",0.06206,{"date":197,"score":126,"percentile":198},"2026-03-16",0.06191,{"date":200,"score":126,"percentile":201},"2026-03-17",0.06177,{"date":203,"score":204,"percentile":205},"2026-03-18",0.00026,0.06852,{"date":207,"score":208,"percentile":209},"2026-03-19",0.00017,0.03706,{"date":211,"score":208,"percentile":212},"2026-03-20",0.03713,{"date":214,"score":208,"percentile":215},"2026-03-21",0.039,{"date":217,"score":208,"percentile":218},"2026-03-22",0.03895,{"date":220,"score":208,"percentile":221},"2026-03-23",0.03894,{"date":223,"score":208,"percentile":224},"2026-03-24",0.03883,{"date":226,"score":208,"percentile":227},"2026-03-25",0.03893,{"date":229,"score":208,"percentile":230},"2026-03-26",0.03904,{"date":232,"score":208,"percentile":233},"2026-03-27",0.03921,{"date":235,"score":208,"percentile":236},"2026-03-28",0.03926,{"date":238,"score":208,"percentile":239},"2026-03-29",0.03918,{"date":241,"score":208,"percentile":242},"2026-03-30",0.03902,{"date":244,"score":208,"percentile":221},"2026-03-31",{"date":246,"score":208,"percentile":247},"2026-04-01",0.03889,{"date":249,"score":208,"percentile":250},"2026-04-02",0.03927,{"date":252,"score":208,"percentile":253},"2026-04-03",0.03942,{"date":255,"score":208,"percentile":256},"2026-04-04",0.03936,{"date":258,"score":208,"percentile":259},"2026-04-05",0.03931,{"date":261,"score":208,"percentile":262},"2026-04-06",0.03935,{"date":264,"score":208,"percentile":265},"2026-04-07",0.03947,{"date":267,"score":208,"percentile":268},"2026-04-08",0.03953,{"date":270,"score":208,"percentile":271},"2026-04-09",0.03978,{"date":273,"score":208,"percentile":274},"2026-04-10",0.03981,{"date":276,"score":208,"percentile":277},"2026-04-11",0.03945,{"date":279,"score":208,"percentile":280},"2026-04-12",0.03928,{"date":282,"score":208,"percentile":283},"2026-04-13",0.03899,{"date":285,"score":208,"percentile":286},"2026-04-14",0.03866,{"date":288,"score":208,"percentile":289},"2026-04-15",0.03863,{"date":291,"score":208,"percentile":292},"2026-04-16",0.03878,{"date":294,"score":208,"percentile":295},"2026-04-17",0.03888,{"date":297,"score":208,"percentile":247},"2026-04-18",{"date":299,"score":208,"percentile":300},"2026-04-19",0.0388,{"date":302,"score":208,"percentile":303},"2026-04-20",0.03865,{"date":305,"score":208,"percentile":306},"2026-04-21",0.04009,{"date":308,"score":208,"percentile":309},"2026-04-22",0.0402,{"date":311,"score":312,"percentile":313},"2026-04-23",0.00019,0.0526,{"date":315,"score":312,"percentile":316},"2026-04-24",0.05252,{"date":318,"score":312,"percentile":319},"2026-04-25",0.05296,{"date":321,"score":312,"percentile":322},"2026-04-26",0.05295,{"date":324,"score":312,"percentile":325},"2026-04-27",0.05286,{"date":327,"score":312,"percentile":328},"2026-04-28",0.05282,{"date":330,"score":312,"percentile":331},"2026-04-29",0.05301,{"date":333,"score":312,"percentile":334},"2026-04-30",0.0531,{"date":336,"score":312,"percentile":337},"2026-05-01",0.05307,{"date":339,"score":312,"percentile":340},"2026-05-02",0.05324,{"date":342,"score":312,"percentile":343},"2026-05-03",0.05311,{"date":345,"score":312,"percentile":346},"2026-05-04",0.05303,{"date":348,"score":312,"percentile":319},"2026-05-05",{"date":350,"score":312,"percentile":351},"2026-05-06",0.05306,{"date":353,"score":312,"percentile":354},"2026-05-07",0.05344,{"date":356,"score":312,"percentile":357},"2026-05-08",0.05343,{"date":359,"score":312,"percentile":360},"2026-05-09",0.05388,{"date":362,"score":312,"percentile":363},"2026-05-10",0.05405,{"date":365,"score":312,"percentile":366},"2026-05-11",0.05397,{"date":368,"score":312,"percentile":369},"2026-05-12",0.05396,{"date":371,"score":312,"percentile":372},"2026-05-13",0.05406,{"date":374,"score":312,"percentile":375},"2026-05-14",0.05398,{"date":377,"score":312,"percentile":378},"2026-05-15",0.05401,[380,385],{"source":83,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":381,"cvss_v4_0":9},{"baseScore":81,"baseSeverity":382,"vectorString":84,"impactScore":383,"exploitabilityScore":384},"HIGH",9.8,4.6,{"source":89,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":386,"cvss_v4_0":9},{"baseScore":81,"baseSeverity":382,"vectorString":84,"impactScore":383,"exploitabilityScore":384},[388,411],{"ecosystem":9,"name":389,"vendor":390,"product":390,"cpe_part":391,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":392},"Linux","linux","a",[393,400,403,406,409],{"version":394,"is_range":395,"range_type":89,"version_start":396,"version_start_type":397,"version_end":398,"version_end_type":399,"fixed_in":9},">= 9e2ee5c7e7c35d195e2aa0692a7241d47a433d1e, \u003C 172dcb67dd35b162357df229d7806acc724cd469",true,"9e2ee5c7e7c35d195e2aa0692a7241d47a433d1e","including","172dcb67dd35b162357df229d7806acc724cd469","excluding",{"version":401,"is_range":395,"range_type":89,"version_start":396,"version_start_type":397,"version_end":402,"version_end_type":399,"fixed_in":9},">= 9e2ee5c7e7c35d195e2aa0692a7241d47a433d1e, \u003C 2889d92c5f728351c9930c7996d22fe6e906e785","2889d92c5f728351c9930c7996d22fe6e906e785",{"version":404,"is_range":395,"range_type":89,"version_start":396,"version_start_type":397,"version_end":405,"version_end_type":399,"fixed_in":9},">= 9e2ee5c7e7c35d195e2aa0692a7241d47a433d1e, \u003C bd25b092a06a3e05f7e8bd6da6fa7318777d8c3d","bd25b092a06a3e05f7e8bd6da6fa7318777d8c3d",{"version":407,"is_range":395,"range_type":89,"version_start":396,"version_start_type":397,"version_end":408,"version_end_type":399,"fixed_in":9},">= 9e2ee5c7e7c35d195e2aa0692a7241d47a433d1e, \u003C e9acda52fd2ee0cdca332f996da7a95c5fd25294","e9acda52fd2ee0cdca332f996da7a95c5fd25294",{"version":410,"is_range":77,"range_type":89,"version_start":410,"version_start_type":397,"version_end":410,"version_end_type":397,"fixed_in":9},"5.15",{"ecosystem":9,"name":412,"vendor":390,"product":413,"cpe_part":414,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":415},"linux kernel","linux_kernel","o",[416,420,422,424,426,428,430,432],{"version":417,"is_range":395,"range_type":418,"version_start":410,"version_start_type":397,"version_end":419,"version_end_type":399,"fixed_in":9},"gte5.15_lt6.18.9","cpe","6.18.9",{"version":421,"is_range":77,"range_type":418,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.19:rc1",{"version":423,"is_range":77,"range_type":418,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.19:rc2",{"version":425,"is_range":77,"range_type":418,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.19:rc3",{"version":427,"is_range":77,"range_type":418,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.19:rc4",{"version":429,"is_range":77,"range_type":418,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.19:rc5",{"version":431,"is_range":77,"range_type":418,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.19:rc6",{"version":433,"is_range":77,"range_type":418,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.19:rc7"]