CVE-2026-23251

In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfarray and xfblob destructor if we have a valid pointer, and be sure to null out that pointer afterwards. Note that this patch fixes a large number of commits, most of which were merged between 6.9 and 6.10.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 May 2026, 18:30

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/5de5be3ed7e7fa4ebde4f4b58fb9a629644f9202 - () https://git.kernel.org/stable/c/5de5be3ed7e7fa4ebde4f4b58fb9a629644f9202 - Patch
References () https://git.kernel.org/stable/c/ba408d299a3bb3c5309f40c5326e4fb83ead4247 - () https://git.kernel.org/stable/c/ba408d299a3bb3c5309f40c5326e4fb83ead4247 - Patch
References () https://git.kernel.org/stable/c/c9ccefacae0d8091683447bc338bd7741417039d - () https://git.kernel.org/stable/c/c9ccefacae0d8091683447bc338bd7741417039d - Patch
References () https://git.kernel.org/stable/c/d827612c81a26cc1dd83a211cfcb5ad8765da0c4 - () https://git.kernel.org/stable/c/d827612c81a26cc1dd83a211cfcb5ad8765da0c4 - Patch
CWE CWE-476
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: xfs: solo llamar a xf{array,blob}_destroy si tenemos un puntero válido Solo llamar al destructor xfarray y xfblob si tenemos un puntero válido, y asegurarse de anular ese puntero después. Tenga en cuenta que este parche soluciona un gran número de commits, la mayoría de los cuales fueron fusionados entre 6.9 y 6.10.

18 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 18:16

Updated : 2026-05-21 18:30


NVD link : CVE-2026-23251

Mitre link : CVE-2026-23251

CVE.ORG link : CVE-2026-23251


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference