---
id: CVE-2026-23459
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS

  Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which
  call iptunnel_xmit_stats()…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS

  Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which
  call iptunnel_xmit_stats()…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.14, < 6.19.10'
  - linux_kernel = 7.0
patched:
  - linux_kernel 6.19.10
published: '2026-04-03'
updated: '2026-09-07'
sourceUpdated: '2026-09-07T16:17:27.923'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23459'
references:
  - url: 'https://git.kernel.org/stable/c/0d087d00161f562d5047cc4009bb0c6a19daf9f1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5d562153b4719234227f99c2fb529f98a6a44d15'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8431c602f551549f082bbfa67f3003f2d8e3e132'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e40e2d11ced8119d3e4469ebe91264bc1cf71530'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00397
epssPercentile: 0.31129
ingestedAt: '2026-07-25T22:05:03.491Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS

Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which
call iptunnel_xmit_stats().

iptunnel_xmit_stats() was assuming tunnels were only using
NETDEV_PCPU_STAT_TSTATS.

@syncp offset in pcpu_sw_netstats and pcpu_dstats is different.

32bit kernels would either have corruptions or freezes if the syncp
sequence was overwritten.

This patch also moves pcpu_stat_type closer to dev->{t,d}stats to avoid
a potential cache line miss since iptunnel_xmit_stats() needs to read it.

## Affected

- `linux_kernel >= 6.14, < 6.19.10`
- `linux_kernel = 7.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.10`
