CVE-2026-23094
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23094 is a denial-of-service vulnerability in the Linux kernel's uacce (Unified/User-space Accelerator Framework) subsystem caused by improper validation of sysfs callback functions in the device isolation feature. It was published on February 4, 2026, and affects Linux kernel versions 6.3 through 6.6.121, 6.7 through 6.12.67, and 6.13 through 6.18.7, as well as pre-release versions 6.19-rc1 through 6.19-rc6. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly).

Technical details

The root cause is improper validation (CWE-476 / null pointer dereference) in the uacce driver's sysfs file creation logic. The uacce subsystem creates sysfs files for isolation error threshold configuration if either the isolate_err_threshold_read or isolate_err_threshold_write callback function is present in the driver; however, when a user accesses the sysfs interface and the corresponding callback does not exist, the kernel attempts to call a null function pointer, causing a system crash. A local attacker with low privileges can trigger this condition by reading or writing to the relevant sysfs path when only one of the two callbacks is implemented by the underlying hardware driver (Feedly).

Impact

Successful exploitation results in a kernel crash, causing a complete denial of service on the affected system. The impact is limited to availability (rated High), with no confidentiality or integrity impact. Because the attack requires only local access with low privileges, any unprivileged user on a system running a vulnerable kernel with uacce-enabled hardware accelerators could bring down the system (Feedly).

Mitigation and workarounds

The Linux kernel maintainers have released patches addressing this issue across all affected stable branches. Users should update to the following patched versions or later: 6.6.122, 6.12.68, 6.18.8, or 6.19-rc7. The fixes are available as four separate stable-tree commits (Feedly). Downstream distributions including SUSE and Ubuntu have also issued updated kernel packages incorporating this fix (SUSE Advisory, Ubuntu Advisory). As a temporary workaround where patching is not immediately possible, restrict local user access and limit privileges on systems running vulnerable kernels with uacce-enabled hardware.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management