Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1192 articles · 101926 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-23417EXPLOITEDPATCHED
linux · linux kernel

bpf: Fix constant blinding for PROBE_MEM32 stores

Description

A vulnerability described as critical has been identified in Linux Kernel up to 6.12.79/6.18.20/6.19.10/7.0-rc4. The impacted element is the function bpf_jit_blind_insn of the component bpf. Executing a manipulation can lead to privilege escalation. This vulnerability is handled as CVE-2026-23417. The attack can only be done within the local network. Upgrading the affected component is recommended.

Affected Products

VendorProductVersions
linuxlinux kernel6082b6c328b5486da2b356eae94b8b83c98b5565, 6082b6c328b5486da2b356eae94b8b83c98b5565, 6082b6c328b5486da2b356eae94b8b83c98b5565, 6082b6c328b5486da2b356eae94b8b83c98b5565, 6.9, 6.12.79, 6.18.20, 6.19.10, 7.0-rc4

References

  • https://git.kernel.org/stable/c/56af722756ed82fee2ae5d5b4d04743407506195
  • https://git.kernel.org/stable/c/ccbf29b28b5554f9d65b2fb53b994673ad58b3bf
  • https://git.kernel.org/stable/c/de641ea08f8fff6906e169d2576c2ac54e562fbb
  • https://git.kernel.org/stable/c/2321a9596d2260310267622e0ad8fbfa6f95378f

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-23417 | Linux Kernel up to 6.12.79/6.18.20/6.19.10/7.0-rc4 bpf bpf_jit_blind_insn privilege escalation
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
56af722756ed82fee2ae5d5b4d04743407506195ccbf29b28b5554f9d65b2fb53b994673ad58b3bfde641ea08f8fff6906e169d2576c2ac54e562fbb2321a9596d2260310267622e0ad8fbfa6f95378f06.12.806.18.216.19.117.0-rc5
PublishedApr 2, 2026
Last enriched4h agov2
Trending Score49
Source articles1
Independent1
Info Completeness7/14
Missing: cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-23413EXP
clsact: Fix use-after-free in init/destroy rollback asymmetry
Trending: 49
CRITICALCVE-2026-23416EXP
mm/mseal: update VMA end correctly on merge
Trending: 49
MEDIUMCVE-2026-22977
In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv_errqueue skbuff_fclone_cache was created without defining a usercopy region, [
Trending: 31
CRITICALCVE-2026-23414
tls: Purge async_hold in tls_decrypt_async_wait()
Trending: 30
CRITICALCVE-2026-23412
netfilter: bpf: defer hook memory release until rcu readers are done
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 2, 2026
Discovered by ZDM
Apr 2, 2026
Actively Exploited
Apr 2, 2026
Patch Available
Apr 2, 2026
Updated: description, affectedVersions, severity, activelyExploited
Apr 2, 2026

Version History

v2
Last enriched 4h ago
v2Tier C4h ago

Updated severity to CRITICAL, added affected versions, and corrected exploit availability.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v14h ago

Initial creation