CVE-2026-23212

Source
https://cve.org/CVERecord?id=CVE-2026-23212
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23212.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23212
Downstream
Published
2026-02-18T14:16:28.104Z
Modified
2026-03-20T12:47:28.549682Z
Summary
bonding: annotate data-races around slave->last_rx
Details

In the Linux kernel, the following vulnerability has been resolved:

bonding: annotate data-races around slave->last_rx

slave->lastrx and slave->targetlastarprx[...] can be read and written locklessly. Add READONCE() and WRITEONCE() annotations.

syzbot reported:

BUG: KCSAN: data-race in bondrcvvalidate / bondrcvvalidate

write to 0xffff888149f0d428 of 8 bytes by interrupt on cpu 1: bondrcvvalidate+0x202/0x7a0 drivers/net/bonding/bondmain.c:3335 bondhandleframe+0xde/0x5e0 drivers/net/bonding/bondmain.c:1533 __netifreceiveskb_core+0x5b1/0x1950 net/core/dev.c:6039 __netifreceiveskbonecore net/core/dev.c:6150 [inline] _netifreceiveskb+0x59/0x270 net/core/dev.c:6265 netifreceiveskbinternal net/core/dev.c:6351 [inline] netifreceiveskb+0x4b/0x2d0 net/core/dev.c:6410 ...

write to 0xffff888149f0d428 of 8 bytes by interrupt on cpu 0: bondrcvvalidate+0x202/0x7a0 drivers/net/bonding/bondmain.c:3335 bondhandleframe+0xde/0x5e0 drivers/net/bonding/bondmain.c:1533 __netifreceiveskb_core+0x5b1/0x1950 net/core/dev.c:6039 __netifreceiveskbonecore net/core/dev.c:6150 [inline] __netifreceiveskb+0x59/0x270 net/core/dev.c:6265 netifreceiveskbinternal net/core/dev.c:6351 [inline] netifreceiveskb+0x4b/0x2d0 net/core/dev.c:6410 brnetifreceiveskb net/bridge/brinput.c:30 [inline] NFHOOK include/linux/netfilter.h:318 [inline] ...

value changed: 0x0000000100005365 -> 0x0000000100005366

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23212.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f5b2b966f032f22d3a289045a5afd4afa09f09c6
Fixed
a7516cb0165926d308187e231ccd330e5e3ebff7
Fixed
8c0be3277e7aefb2f900fc37ca3fe7df362e26f5
Fixed
b956289b83887e0a306067b6003c3fcd81bfdf84
Fixed
bd98324e327e41de04b13e372cc16f73150df254
Fixed
f6c3665b6dc53c3ab7d31b585446a953a74340ef

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23212.json"