PT-2026-4664 · Linux+3 · Linux Kernel+3

CVE-2026-23002

·

Published

2026-01-01

·

Updated

2026-08-21

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s lib/buildid component related to handling kernel NULL pointer dereferences during file reading in sleepable contexts. Specifically, the issue involves using direct page cache access via read cache folio() which can lead to a kernel crash. The resolution involves converting to kernel read() for sleepable contexts to utilize the standard kernel file reading interface, simplifying the faultable code path. The fix prevents a "BUG: unable to handle kernel NULL pointer dereference in filemap read folio". The initial fix focuses on sleepable contexts to simplify backporting to stable kernels, with plans for future improvements to support non-sleepable contexts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47040
BDU:2026-01112
CVE-2026-23002
OPENSUSE-SU-2026:20287-1
RHSA-2026:18134
RHSA-2026:47040
SUSE-SU-2026:20555-1
SUSE-SU-2026:20570-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
USN-8570-1
USN-8570-2
USN-8594-1
USN-8604-1
USN-8605-1
USN-8669-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu