Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23219

20
FAUCET Score

Overview: CVE-2026-23219 describes a vulnerability in the Linux kernel related to memory management (mm/slab). Specifically, when CONFIG_MEM_ALLOC_PROFILING_DEBUG is enabled, a warning can be triggered because the alloc_tag is not properly cleared during certain memory allocation failure scenarios within the memcg_alloc_abort_single function. This issue affects the Linux kernel. Severity: The vulnerability's severity is low, as indicated by its lack of a CVSS score and a low FAUCET Risk Score of 20/100. It appears to be a debugging-related issue that manifests as a warning rather than a direct security exploit. There is no information suggesting a direct attack vector or complex exploitation, and the potential impact seems limited to system instability or diagnostic noise when the specific debug configuration is active. Exploitation Status: There is no evidence of active exploitation for CVE-2026-23219. No exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Furthermore, the vulnerability has garnered no community discussion or media coverage, suggesting a low level of attention and perceived threat.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.10, < 6.12.70CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.18.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 10th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2026-23219Moderate

kernel: mm/slab: Add alloc_tagging_slab_free_hook for memcg_alloc_abort_single

Feb 18, 2026

References

git.kernel.org / stable/c/b8bc72587c79fe52c14732e16a766b6eded00707
Patch
git.kernel.org / stable/c/e6c53ead2d8fa73206e0a63e9cd9aea6bc929837
Patch
git.kernel.org / stable/c/e8af57e090790983591f6927b3d89ee6383f8c1e
Patch