CVE-2026-23348 addresses a race condition in the Linux kernel's CXL (Compute Express Link) subsystem, specifically affecting the handling of NVDIMM objects. This flaw can lead to a NULL pointer dereference and a kernel crash when the `cxl_acpi` module is removed, causing orphaned NVDIMM objects to reprobe without the necessary bus object. The vulnerability's complexity and specific trigger conditions suggest a low likelihood of exploitation, with the primary impact being a denial of service. There is currently no evidence of active exploitation, public exploit code, or significant community attention for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.14.1, < 6.18.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.19, < 6.19.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.14:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.