CVE-2026-23252
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23252 is a denial-of-service vulnerability in the Linux kernel's XFS filesystem subsystem, caused by memory allocation failures in the xchk_xfile_*_descr macros. These macros invoke kasprintf, which can fail to allocate memory when formatting strings exceeding 16 bytes, a condition discoverable via syzbot fuzzing by researcher Jiaming Zhang. The vulnerability was disclosed on March 18, 2026, and affects Linux kernel versions 6.10–6.12 (before 6.12.78), 6.13–6.18 (before 6.18.16), and 6.19+ (before 6.19.6). It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper handling of memory allocation failures (CWE-400: Uncontrolled Resource Consumption) in the XFS online checker (xchk) subsystem. The xchk_xfile_*_descr macros call kasprintf to format debug description strings; when the resulting string exceeds the kernel's nofail allocation threshold (~16 bytes), the allocation can fail, leading to a NULL pointer dereference or kernel panic. The fix replaces dynamic formatted strings with static strings, eliminating the failure path entirely. The vulnerability requires local access with permissions to perform XFS filesystem checker operations, and was identified through syzbot kernel fuzzing (Red Hat Bugzilla, Feedly).

Impact

Successful exploitation results in a kernel crash or system hang, constituting a denial-of-service condition. There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the local system; an attacker cannot leverage this vulnerability for lateral movement or data exfiltration (Red Hat Advisory, Feedly).

Mitigation and workarounds

Update the Linux kernel to a patched version: 6.12.78 or later (for the 6.10–6.12 branch), 6.18.16 or later (for the 6.13–6.18 branch), or 6.19.6 or later (for the 6.19+ branch). Patches are available in the Linux kernel stable branches via git.kernel.org. No configuration-based workaround is documented; upgrading to a fixed kernel version is the recommended remediation (Red Hat Advisory, Red Hat Bugzilla).

Community reactions

Red Hat triaged this as low severity/priority in their Bugzilla tracker, consistent with the local-only, availability-only impact. Debian also issued an advisory (DSA-6238-1) covering this and related Linux kernel vulnerabilities. No notable researcher commentary or significant social media discussion has been observed beyond standard vulnerability tracking (Red Hat Bugzilla, Linux Security Debian).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management