CVE-2026-23083
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/02/2026
Last modified:
04/02/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
fou: Don&#39;t allow 0 for FOU_ATTR_IPPROTO.<br />
<br />
fou_udp_recv() has the same problem mentioned in the previous<br />
patch.<br />
<br />
If FOU_ATTR_IPPROTO is set to 0, skb is not freed by<br />
fou_udp_recv() nor "resubmit"-ted in ip_protocol_deliver_rcu().<br />
<br />
Let&#39;s forbid 0 for FOU_ATTR_IPPROTO.



