CVE-2026-23212 PUBLISHED

bonding: annotate data-races around slave->last_rx

Assigner: Linux
Reserved: 13.01.2026 Published: 18.02.2026 Updated: 18.02.2026

In the Linux kernel, the following vulnerability has been resolved:

bonding: annotate data-races around slave->last_rx

slave->last_rx and slave->target_last_arp_rx[...] can be read and written locklessly. Add READ_ONCE() and WRITE_ONCE() annotations.

syzbot reported:

BUG: KCSAN: data-race in bond_rcv_validate / bond_rcv_validate

write to 0xffff888149f0d428 of 8 bytes by interrupt on cpu 1: bond_rcv_validate+0x202/0x7a0 drivers/net/bonding/bond_main.c:3335 bond_handle_frame+0xde/0x5e0 drivers/net/bonding/bond_main.c:1533 __netif_receive_skb_core+0x5b1/0x1950 net/core/dev.c:6039 __netif_receive_skb_one_core net/core/dev.c:6150 [inline] __netif_receive_skb+0x59/0x270 net/core/dev.c:6265 netif_receive_skb_internal net/core/dev.c:6351 [inline] netif_receive_skb+0x4b/0x2d0 net/core/dev.c:6410 ...

write to 0xffff888149f0d428 of 8 bytes by interrupt on cpu 0: bond_rcv_validate+0x202/0x7a0 drivers/net/bonding/bond_main.c:3335 bond_handle_frame+0xde/0x5e0 drivers/net/bonding/bond_main.c:1533 __netif_receive_skb_core+0x5b1/0x1950 net/core/dev.c:6039 __netif_receive_skb_one_core net/core/dev.c:6150 [inline] __netif_receive_skb+0x59/0x270 net/core/dev.c:6265 netif_receive_skb_internal net/core/dev.c:6351 [inline] netif_receive_skb+0x4b/0x2d0 net/core/dev.c:6410 br_netif_receive_skb net/bridge/br_input.c:30 [inline] NF_HOOK include/linux/netfilter.h:318 [inline] ...

value changed: 0x0000000100005365 -> 0x0000000100005366

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from f5b2b966f032f22d3a289045a5afd4afa09f09c6 to a7516cb0165926d308187e231ccd330e5e3ebff7 (excl.)
  • affected from f5b2b966f032f22d3a289045a5afd4afa09f09c6 to 8c0be3277e7aefb2f900fc37ca3fe7df362e26f5 (excl.)
  • affected from f5b2b966f032f22d3a289045a5afd4afa09f09c6 to b956289b83887e0a306067b6003c3fcd81bfdf84 (excl.)
  • affected from f5b2b966f032f22d3a289045a5afd4afa09f09c6 to bd98324e327e41de04b13e372cc16f73150df254 (excl.)
  • affected from f5b2b966f032f22d3a289045a5afd4afa09f09c6 to f6c3665b6dc53c3ab7d31b585446a953a74340ef (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.19 is affected
  • unaffected from 0 to 2.6.19 (excl.)
  • unaffected from 6.1.162 to 6.1.* (incl.)
  • unaffected from 6.6.123 to 6.6.* (incl.)
  • unaffected from 6.12.69 to 6.12.* (incl.)
  • unaffected from 6.18.9 to 6.18.* (incl.)
  • unaffected from 6.19 to * (incl.)

References