CVE-2026-23249 describes a null pointer dereference vulnerability in the Linux kernel's XFS filesystem. This flaw occurs during the revalidation of free space and inode btrees, where an error condition in the first revalidation step can inadvertently nullify a cursor needed by the subsequent step, leading to a system crash. The vulnerability, likely triggered via specific XFS ioctl calls, primarily results in a denial-of-service impact. Its low FAUCET Risk Score (20.0/100) and extremely low EPSS (0.000230000) suggest a limited practical impact and difficulty in exploitation. There is no evidence of active exploitation, nor are public exploit codes available, and community and media attention for this CVE remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.8, < 6.12.75CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.18.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.19, < 6.19.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel (FIPS) vulnerabilities
Jul 10, 2026Linux kernel (Raspberry Pi Real-time) vulnerabilities
Jul 6, 2026Linux kernel (Xilinx) vulnerabilities
Jul 2, 2026Linux kernel (NVIDIA Tegra) vulnerabilities
Jul 2, 2026Linux kernel (Low Latency) vulnerabilities
Jul 2, 2026Linux kernel vulnerabilities
Jul 2, 2026Linux kernel vulnerabilities
Jul 1, 2026