CVE-2026-23360
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23360 is a memory leak vulnerability in the Linux kernel's NVMe subsystem, specifically in the admin queue management during controller reset operations. When nvme_alloc_admin_tag_set() is called during a controller reset, a previously existing admin queue is not properly released before a new one is allocated, resulting in orphaned queue objects. This is a regression introduced by commit 03b3bcd319b3 ("nvme: fix admin request_queue lifetime"). Affected kernel versions include ranges from 6.6.120 through 6.19.x and 6.18, with patches available in 6.6.131+, 6.12.77+, 6.18.17+, 6.19.7+, and 7.0-rc3+. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-772 (Missing Release of Resource after Effective Lifetime) and CWE-401 (Missing Release of Memory after Effective Lifetime). During an NVMe controller reset, the kernel calls nvme_alloc_admin_tag_set() without first checking whether a prior admin queue already exists and releasing it; the old queue object is orphaned in kernel memory. Exploitation requires local access with low privileges — an attacker or process capable of triggering repeated NVMe controller resets can cause cumulative kernel memory leakage. No public proof-of-concept exploit code has been identified (Red Hat Bugzilla, Red Hat Advisory).

Impact

Successful exploitation leads exclusively to availability impact — there is no confidentiality or integrity compromise. Repeated NVMe controller reset operations cause orphaned admin queue objects to accumulate in kernel memory, potentially exhausting kernel memory resources and resulting in denial of service, system performance degradation, or system instability. The vulnerability is limited to local exploitation and does not enable lateral movement or data exfiltration (Red Hat Advisory).

Mitigation and workarounds

The Linux kernel maintainers have released patches addressing this vulnerability in the following versions: 6.6.131+, 6.12.77+, 6.18.17+, 6.19.7+, and 7.0-rc3+. Patch commits are available from kernel.org stable trees. As interim mitigations, administrators should restrict local user access and limit the ability of unprivileged users to trigger NVMe controller resets, and monitor kernel memory usage for unexpected increases that could indicate queue object leakage. Applying kernel updates as part of regular patching cycles is the recommended long-term solution (Red Hat Advisory, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management