CVE-2026-23298 | Linux Kernel up to 7.0-rc2 ucan ucan_read_bulk_callback length infinite loop (Nessus ID 311783 / WID-SEC-2026-0861)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.0-rc2. This vulnerability affects the function ucan_read_bulk_callback of the component ucan. Executing a manipulation of the argument length can lead to infinite loop.
This vulnerability is handled as CVE-2026-23298. The attack can only be done within the local network. There is not any exploit available.
You should upgrade the affected component.