PT-2026-27692 · Linux · Linux Kernel

CVE-2026-23327

·

Published

2026-01-01

·

Updated

2026-08-30

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.19.0
Description The Linux kernel contains a flaw in the cxl/mbox subsystem. Specifically, the cxl payload from user allowed() function casts and dereferences input payload data without first verifying its size. This can lead to a read-access violation when a raw mailbox command is sent with an undersized payload, such as a 1-byte payload for an operation expecting a 16-byte UUID. This results in reading past the allocated buffer, triggering a kernel memory safety issue.
Recommendations Update to Linux kernel version 6.19.0 or later.

Exploit

Fix

Out of bounds Read

Buffer Over-read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12325
CVE-2026-23327
OPENSUSE-SU-2026:20965-1
SUSE-SU-2026:22099-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22112-1
SUSE-SU-2026:22117-1
SUSE-SU-2026:22127-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1

Affected Products

Linux Kernel