PT-2026-27719 · Linux · Linux Kernel

CVE-2026-23354

·

Publicado

2026-01-01

·

Atualizado

2026-08-30

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel's x86/fred component related to speculative safety within the fred extint() function. The array index nospec() function was not effectively utilized to prevent memory predictions, as the calculated index was stored on the stack, making it vulnerable. The issue stemmed from the incorrect placement of array index nospec() relative to the array access, specifically occurring after irqentry enter() and involving the index variable being placed in %ebp across a function call. The correction involves repositioning array index nospec() to be calculated immediately before the array access and removing the index variable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-12166
CVE-2026-23354
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1

Produtos afetados

Linux Kernel