CVE-2026-23217 describes a deadlock vulnerability in the Linux kernel affecting RISC-V systems. Specifically, enabling function tracing for sbi_ecall.c functions can trigger an infinite loop when a snapshot is initiated, as the snapshot process itself calls sbi_ecall, leading to recursive snapshots. This can easily be triggered on RISC-V systems without the SSTC extension due to periodic sbi ecalls. The vulnerability has no assigned CVSS score, but its FAUCET Risk Score is 20/100, indicating a moderate risk. The attack vector involves enabling specific tracing, leading to a denial of service through system deadlock. The fix involves always excluding sbi_ecall.c functions from tracing. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, with only one mention and one article identified, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.10.10, < 6.11CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.10.10, < 6.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.11.1, < 6.18.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.11:-:*:*:*:*:*:* | ||
6.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.11:rc7:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.