Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2026-23379 — kernel

🟡 CVSS 5.5 — Medium ✅ No Known Exploit NVD
5.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

net/sched: ets: fix divide by zero in the offload path

In the Linux kernel, the following vulnerability has been resolved:

net/sched: ets: fix divide by zero in the offload path

Offloading ETS requires computing each class' WRR weight: this is done by

averaging over the sums of quanta as 'q_sum' and 'q_psum'. Using unsigned

int, the same integer size as the individual DRR quanta, can overflow and

even cause division by zero, like it happened in the following splat:

Oops: divide error: 0000 [#1] SMP PTI

CPU: 13 UID: 0 PID: 487 Comm: tc Tainted: G E 6.19.0-virtme #45 PREEMPT(full)

Tainted: [E]=UNSIGNED_MODULE

Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011

RIP: 0010:ets_offload_change+0x11f/0x290 [sch_ets]

Code: e4 45 31 ff eb 03 41 89 c7 41 89 cb 89 ce 83 f9 0f 0f 87 b7 00 00 00 45 8b 08 31 c0 45 01 cc 45 85 c9 74 09 41 6b c4 64 31 d2 <41> f7 f2 89 c2 44 29 fa 45 89 df 41 83 fb 0f 0f 87 c7 00 00 00 44

RSP: 0018:ffffd0a180d77588 EFLAGS: 00010246

RAX: 00000000ffffff38 RBX: ffff8d3d482ca000 RCX: 0000000000000000

RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffd0a180d77660

RBP: ffffd0a180d77690 R08: ffff8d3d482ca2d8 R09: 00000000fffffffe

R10: 0000000000000000 R11: 0000000000000000 R12: 00000000fffffffe

R13: ffff8d3d472f2000 R14: 0000000000000003 R15: 0000000000000000

FS: 00007f440b6c2740(0000) GS:ffff8d3dc9803000(0000) knlGS:0000000000000000

CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033

CR2: 000000003cdd2000 CR3: 0000000007b58002 CR4: 0000000000172ef0

Call Trace:

<TASK>

ets_qdisc_change+0x870/0xf40 [sch_ets]

qdisc_create+0x12b/0x540

tc_modify_qdisc+0x6d7/0xbd0

rtnetlink_rcv_msg+0x168/0x6b0

netlink_rcv_skb+0x5c/0x110

netlink_unicast+0x1d6/0x2b0

netlink_sendmsg+0x22e/0x470

____sys_sendmsg+0x38a/0x3c0

___sys_sendmsg+0x99/0xe0

__sys_sendmsg+0x8a/0xf0

do_syscall_64+0x111/0xf80

entry_SYSCALL_64_after_hwframe+0x77/0x7f

RIP: 0033:0x7f440b81c77e

Code: 4d 89 d8 e8 d4 bc 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 <c9> c3 83 e2 39 83 fa 08 75 e7 e8 13 ff ff ff 0f 1f 00 f3 0f 1e fa

RSP: 002b:00007fff951e4c10 EFLAGS: 00000202 ORIG_RAX: 000000000000002e

RAX: ffffffffffffffda RBX: 0000000000481820 RCX: 00007f440b81c77e

RDX: 0000000000000000 RSI: 00007fff951e4cd0 RDI: 0000000000000003

RBP: 00007fff951e4c20 R08: 0000000000000000 R09: 0000000000000000

R10: 0000000000000000 R11: 0000000000000202 R12: 00007fff951f4fa8

R13: 00000000699ddede R14: 00007f440bb01000 R15: 0000000000486980

</TASK>

Modules linked in: sch_ets(E) netdevsim(E)

---[ end trace 0000000000000000 ]---

RIP: 0010:ets_offload_change+0x11f/0x290 [sch_ets]

Code: e4 45 31 ff eb 03 41 89 c7 41 89 cb 89 ce 83 f9 0f 0f 87 b7 00 00 00 45 8b 08 31 c0 45 01 cc 45 85 c9 74 09 41 6b c4 64 31 d2 <41> f7 f2 89 c2 44 29 fa 45 89 df 41 83 fb 0f 0f 87 c7 00 00 00 44

RSP: 0018:ffffd0a180d77588 EFLAGS: 00010246

RAX: 00000000ffffff38 RBX: ffff8d3d482ca000 RCX: 0000000000000000

RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffd0a180d77660

RBP: ffffd0a180d77690 R08: ffff8d3d482ca2d8 R09: 00000000fffffffe

R10: 0000000000000000 R11: 0000000000000000 R12: 00000000fffffffe

R13: ffff8d3d472f2000 R14: 0000000000000003 R15: 0000000000000000

FS: 00007f440b6c2740(0000) GS:ffff8d3dc9803000(0000) knlGS:0000000000000000

CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033

CR2: 000000003cdd2000 CR3: 0000000007b58002 CR4: 0000000000172ef0

Kernel panic - not syncing: Fatal exception

Kernel Offset: 0x30000000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)

---[ end Kernel panic - not syncing: Fatal exception ]---

Fix this using 64-bit integers for 'q_sum' and 'q_psum'.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

CVE-2026-23379 is recorded against 2 packages.

  • kernel (from 6.19.0 up to 6.19.7)
  • linux-kernel

Timeline and source

Published on 25 March 2026 and last revised on 12 August 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

cert-portal.siemens.com (Web)
cert-portal.siemens.com (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2026-23379 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Medium
CVSS Score 5.5
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2026-03-25
Updated 2026-08-20
Modified 2026-08-12

Affected Packages

Software From version Fixed in
kernel 6.19.0 6.19.7
linux-kernel

References

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in kernel

CVE-2026-23379 is rated CVSS 5.5 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.