PT-2026-27739 · Linux+2 · Linux Kernel+2

CVE-2026-23374

·

Publicado

2026-01-01

·

Atualizado

2026-08-30

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.0-rc1lblk+ #84
Description The Linux kernel's blktrace component contains an issue where this cpu read() and this cpu write() are used in a preemptible context. Specifically, tracing record cmdline() utilizes these functions on the per-CPU variable trace cmdline save, but does not ensure preemption is disabled. This occurs when calling tracing record cmdline(current) early in the blk tracer path, before ring buffer reservation. This can lead to a kernel bug, as observed in testing with blktrace/002, resulting in a crash. The issue affects multiple paths including blk add trace plug(), blk add trace unplug(), and blk add trace rq().
Recommendations Update to a version of the Linux kernel that addresses this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-80709
BDU:2026-12337
CVE-2026-23374
ECHO-B1E9-58AF-CBE9
OESA-2026-2418
OESA-2026-2493
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Produtos afetados

Linuxmint
Linux Kernel
Ubuntu