Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23115

18
FAUCET Score

Overview: CVE-2026-23115 addresses a race condition in the Linux kernel's serial driver, specifically affecting how tty devices are linked to their ports. This vulnerability occurs when user-space attempts to open a console before the tty->port is properly configured, leading to a kernel crash. It primarily impacts systems using Qualcomm SoCs with fast boot sequences and a serial console. Severity: The vulnerability has a FAUCET Risk Score of 20/100, indicating a low to moderate severity. The attack vector is local, requiring user-space interaction to trigger the race condition. The complexity is relatively low, as it can be consistently reproduced under specific boot conditions. The potential impact is a kernel crash, leading to system instability and denial of service. Exploitation Status: There is no evidence of active exploitation for CVE-2026-23115. No exploit code is publicly available on platforms like Metasploit, Nuclei, or ExploitDB. Community attention and media coverage are minimal, with zero mentions on social media or in news articles, suggesting it is not a widely discussed or exploited vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.15, < 6.18.8CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.07%
Probability of exploitation in next 30 days
EPSS Percentile
0.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0007 is in the 3rd percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

ubuntupatch availablevia ubuntu_usn
Product: linux-gcp-6.17 (noble)Fixed in: 6.17.0-1021.24~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-realtime-6.17 (noble)Fixed in: 6.17.0-1018.20~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-oem-6.17 (noble)Fixed in: 6.17.0-1030.30
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fde-6.17 (noble)Fixed in: 6.17.0-1018.18~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.17 (noble)Fixed in: 6.17.0-1021.21~24.04.1

Vendor Advisories (5)

ubuntuUSN-8605-1

Linux kernel (Azure CVM) vulnerabilities

Jul 24, 2026
ubuntuUSN-8604-1

Linux kernel (Azure) vulnerabilities

Jul 24, 2026
ubuntuUSN-8594-1

Linux kernel (OEM) vulnerabilities

Jul 23, 2026
ubuntuUSN-8570-1

Linux kernel vulnerabilities

Jul 20, 2026
redhatCVE-2026-23115

kernel: serial: Fix not set tty->port race condition

Feb 14, 2026

References

git.kernel.org / stable/c/2501c49306238b54a2de0f93de43d50ab6e76c84
Patch
git.kernel.org / stable/c/32f37e57583f869140cff445feedeea8a5fea986
Patch