CVE-2026-23327 identifies an out-of-bounds read vulnerability in the Linux kernel's CXL (Compute Express Link) mailbox driver. Specifically, the `cxl_payload_from_user_allowed()` function fails to validate the size of an input payload, leading to attempts to read beyond allocated memory when an undersized payload is provided. This flaw can result in a kernel crash (Denial of Service), as indicated by a KASAN slab-out-of-bounds error. The vulnerability is assessed with a low FAUCET Risk Score of 20.0/100 and a very low EPSS score, reflecting its limited potential impact. There is no evidence of active exploitation, public exploit code is unavailable, and community attention remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.19.1, < 6.19.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.19:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.