CVE-2026-23276 | Linux Kernel up to 6.18.18/6.19.8/7.0-rc3 net bond_xmit_broadcast recursion (EUVD-2026-13612 / WID-SEC-2026-0809)
A vulnerability was found in Linux Kernel up to 6.18.18/6.19.8/7.0-rc3. It has been rated as critical. Affected by this issue is the function bond_xmit_broadcast of the component net. Performing a manipulation results in uncontrolled recursion.
This vulnerability was named CVE-2026-23276. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.