CVE-2026-23003 | Linux Kernel up to 6.12.66/6.18.6/6.19-rc5 ip6_tunnel include/net/inet_ecn.h skb_vlan_inet_prepare information disclosure (EUVD-2026-4621 / Nessus ID 296526)
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.66/6.18.6/6.19-rc5. Affected by this issue is the function skb_vlan_inet_prepare in the library include/net/inet_ecn.h of the component ip6_tunnel. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-23003. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.