CVE-2026-23004 is a race condition in the Linux kernel destination-cache uncached route-list deletion paths, affecting the IPv6 rt6_uncached_list_del() function and the analogous IPv4 rt_del_uncached_list() path. Concurrent list manipulation can cause rt6_uncached_list_del() to treat a partially updated list as empty and bypass locking while another CPU updates the list. This permits list cleanup to access an already freed route-list object, causing a slab use-after-free in INIT_LIST_HEAD() or list_del_init() during IPv6 route, address, network-device, or network-namespace cleanup.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for CVE-2026-23004, demonstrating an automotive Unified Diagnostic Services (UDS) authentication bypass via replay attack. The repository contains three files: an MIT LICENSE, a README describing the issue and usage, and a single Python script, uds_sim.py, which implements the exploit simulation. The Python code defines a simple ECU class with a static secret, an 8-byte random challenge generator, and a response verifier that accepts the first 8 bytes of SHA-256(secret || challenge). The exploit flow is straightforward: a valid challenge-response pair is generated once, then the same challenge and response are reused by resetting ecu.challenge to the previously captured value and calling verify_response again. The script then calls unlock(), printing that critical functions are accessible. This demonstrates the core vulnerability: failure to enforce one-time challenge usage or invalidate previously used challenges. There are no real network, CAN, or UDS transport interactions in the code; it is a local simulation only. As such, there are no hardcoded IPs, domains, sockets, registry keys, or external command-and-control endpoints. The only notable target reference is UDS Security Access service 0x27 mentioned in the README. Overall, this is a concise educational exploit PoC showing replay-based authentication bypass logic rather than a weaponized exploit against a live automotive target.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel race-condition use-after-free vulnerability affecting IPv4 and IPv6 uncached route-list deletion. Concurrent list manipulation can result in access to a freed list object, causing a kernel crash and denial of service.
A Qualys-disclosed set of multiple AppArmor vulnerabilities, collectively referred to as CrackArmor, affecting Linux systems using AppArmor. The issues include a confused-deputy flaw enabling arbitrary profile load/replace/remove, bypass of Ubuntu user-namespace restrictions, denial of service, and multiple local privilege escalation paths including kernel memory corruption bugs.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.