Improper locking in Linux kernel - CVE-2026-23199
Published: February 16, 2026
Vulnerability identifier: #VU122904
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23199
CWE-ID: CWE-667
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the get_build_id_64(), __build_id_parse() and build_id_parse_nofault() functions in lib/buildid.c. A local user can perform a denial of service (DoS) attack.
Affected software
Linux kernel
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
kernel (Red Hat package)
linux (Debian package)
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
kernel (Red Hat package)
linux (Debian package)
How to mitigate CVE-2026-23199
Install update from vendor's repository.
kernel (Red Hat package) - update to 6.12.0-211.43.1.el10_2
linux (Debian package) - update to 6.12.73-1
linux (Debian package) - update to 6.12.73-1