Microsoft published security advisories for two Linux kernel vulnerabilities tracked as CVE-2026-23381 and CVE-2026-23356. The first affects the networking stack's bridge code, where nd_tbl can be dereferenced as NULL when IPv6 is disabled, creating a stability and potential denial-of-service risk in affected systems.
The second advisory covers a logic bug in the Distributed Replicated Block Device (DRBD) subsystem, specifically in drbd_al_begin_io_nonblock(). Together, the disclosures highlight flaws in both kernel networking and storage-replication paths that administrators should review in Microsoft-tracked update guidance and remediate through available vendor patches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft added CVE-2026-23397 to its Security Update Guide, describing a fix related to nfnetlink_osf and validation of individual option lengths in fingerprints.
Microsoft added CVE-2026-23381 to its Security Update Guide, describing a fix for a net/bridge nd_tbl NULL dereference issue when IPv6 is disabled.
Microsoft added CVE-2026-23356 to its Security Update Guide, describing a fix for a DRBD logic bug in drbd_al_begin_io_nonblock().
Microsoft added CVE-2026-23293 to its Security Update Guide, describing a fix for a VXLAN nd_tbl NULL dereference issue when IPv6 is disabled.
7 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.