CVE-2026-23001 is a possible use-after-free vulnerability in the Linux kernel macvlan networking subsystem. Insufficient RCU protection of the vlan pointer in struct macvlan_source_entry can allow macvlan_forward_source() to access objects associated with entries queued for freeing. The fix adds RCU protection to that pointer and requires macvlan_hash_del_source() to clear entry->vlan before the RCU grace period begins, allowing forwarding to skip entries pending release. The flaw can cause kernel memory corruption and crashes, with potential local privilege escalation depending on configuration and exploitability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Python proof-of-concept for insecure deserialization leading to code execution in PyTorch/Hugging Face model-loading workflows. It contains two code files: `malicious_model_card.py`, which generates a fake model package, and `exploit_hf_pickle.py`, which simulates a victim loading the malicious artifact. The core exploit primitive is a Python class with a crafted `__reduce__` method that returns `(os.system, ('id > /tmp/hf_pwned',))`. When the serialized object is later deserialized via `torch.load('pytorch_model.bin')`, the pickle machinery invokes `os.system`, causing command execution. The repository does not include networking or callback infrastructure; it is a local file-based deserialization exploit demonstrating how a malicious model file can act as a supply-chain attack artifact. Structure-wise, `README.md` explains the vulnerability and usage, `malicious_model_card.py` writes `config.json` and a malicious `pytorch_model.bin`, and `exploit_hf_pickle.py` triggers the vulnerable load path. The exploit capability is arbitrary command execution at model load time, with the included payload simply creating `/tmp/hf_pwned` as evidence.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A possible use-after-free vulnerability in the Linux kernel's macvlan_forward_source() function. The fix adds RCU protection to the source entry's vlan pointer and clears it before the RCU grace period begins, allowing forwarding to skip entries queued for freeing. The plugin reports a CVSS v3 base score of 7.8, indicating a local, low-complexity attack requiring low privileges, with potentially high confidentiality, integrity, and availability impacts.
A possible use-after-free vulnerability in the Linux kernel's macvlan_forward_source() function. The fix adds RCU protection and clears the entry->vlan pointer before the RCU grace period starts, allowing forwarding to skip entries queued for freeing. The listed CVSS v3 score is 7.8, with local access, low privileges, no user interaction, and high confidentiality, integrity, and availability impacts. The advisory recommends updating linux and related packages to version 6.1.162-1 or later.
A use-after-free vulnerability in the Linux kernel's macvlan_forward_source() function involving insufficient RCU protection of a macvlan source entry's vlan pointer. The fix clears the pointer before the RCU grace period begins, allowing forwarding to skip entries queued for freeing. The plugin identifies affected Google kernel packages and assigns a CVSS v3 score of 7.8, with local access and low privileges required.
A possible use-after-free vulnerability in the Linux kernel macvlan component's macvlan_forward_source() function. It affects Rocky Linux 8 kernel packages covered by CIQ advisory crlsa-2026_3963.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.