CVE-2026-23099 | Linux Kernel up to 6.6.121/6.12.67/6.18.7/6.19-rc6 bonding dev_addr_lists.c __hw_addr_create out-of-bounds (Nessus ID 297925)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.121/6.12.67/6.18.7/6.19-rc6. This affects the function __hw_addr_create of the file net/core/dev_addr_lists.c of the component bonding. This manipulation causes out-of-bounds read.
This vulnerability is registered as CVE-2026-23099. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.