In the Linux kernel, the following vulnerability has been resolved:
mtd: rawnand: serialize lock/unlock against other NAND operations
nand_lock() and nand_unlock() call into chip->ops.lock_area/unlock_area
without holding the NAND device lock. On controllers that implement
SET_FEATURES via multiple low-level PIO commands, these can race with
concurrent UBI/UBIFS background erase/write operations that hold the
device lock, resulting in cmd_pending conflicts on the NAND controller.
Add nand_get_device()/nand_release_device() around the lock/unlock
operations to serialize them against all other NAND controller access.
References
Configurations
Configuration 1 (hide)
|
History
24 Jul 2026, 21:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
14 Jul 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
27 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
23 Apr 2026, 20:59
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| First Time |
Linux
Linux linux Kernel |
|
| CPE | cpe:2.3:o:linux:linux_kernel:5.7:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* |
|
| References | () https://git.kernel.org/stable/c/28ea836cc44cb8b89c1c174707ead0c1133c60e9 - Patch | |
| References | () https://git.kernel.org/stable/c/5fd5c078af23cb353507aa522e09d557d7eaef04 - Patch | |
| References | () https://git.kernel.org/stable/c/a80291e577b44593a724d6cd64c14337c78f194d - Patch | |
| References | () https://git.kernel.org/stable/c/bab2bc6e850a697a23b9e5f0e21bb8c187615e95 - Patch | |
| References | () https://git.kernel.org/stable/c/ce5229e78078e437704157eb542f43a6f83b429b - Patch | |
| References | () https://git.kernel.org/stable/c/f25446e2c28939753d3b62d34dfda49952b2557d - Patch | |
| References | () https://git.kernel.org/stable/c/f71ce0ae5aefe39dd5b2f996c0e08550d2153ad2 - Patch | |
| References | () https://git.kernel.org/stable/c/fe4a73c3dd48308149d57a10c2761e1d36ced7ba - Patch | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
18 Apr 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
03 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-03 16:16
Updated : 2026-07-24 21:10
NVD link : CVE-2026-23434
Mitre link : CVE-2026-23434
CVE.ORG link : CVE-2026-23434
JSON object : View
Products Affected
linux
- linux_kernel
CWE
