Exposed IOCTL with Insufficient Access Control in Linux kernel - CVE-2026-23257
Published: March 20, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an off-by-one error in the PF setup_nic_devices() function in the liquidio network driver when handling device initialization cleanup. A local user can trigger improper cleanup of allocated resources to cause a denial of service.
The vulnerability specifically results in a memory leak during device setup failure, which may lead to resource exhaustion over time. Administrative privileges are required to trigger the device setup process.
Affected software
Ubuntu
linux (Ubuntu package)
linux-xilinx-zynqmp (Ubuntu package)
linux-raspi (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-fips (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
How to mitigate CVE-2026-23257
linux (Ubuntu package) - addressed in versions 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-117.117, 6.8.0-117.117.1, 6.8.0-117.117.1~22.04.1, 6.8.0-1041.44, 6.8.0-1054.60, 6.8.0-1055.56, 6.8.0-1055.56~22.04.1, 6.8.0-1055.58+fips1, 6.8.0-1056.60, 6.8.0-1058.61, 6.8.0-1058.61+fips1, 6.8.0-2045.46, 6.8.1-1051.52, 6.8.1-1051.52~22.04.1
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-raspi (Ubuntu package) - addressed in versions 5.15.0.1105.103, 5.15.0-1105.108
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1
linux-fips (Ubuntu package) - update to 6.8.0-116.116+fips1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1024.24
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1054.57, 6.8.0-1054.57.1
linux-nvidia-6.8 (Ubuntu package) - update to 6.8.0-1054.57~22.04.1
linux-azure (Ubuntu package) - update to 6.8.0-1056.62
External References
- https://git.kernel.org/stable/c/293eaad0d6d6b2a37a458c7deb7be345349cd963
- https://git.kernel.org/stable/c/8558aef4e8a1a83049ab906d21d391093cfa7e7f
- https://git.kernel.org/stable/c/a0d2389c8cdc1f05de5eb8663bffe9ed05dca769
- https://git.kernel.org/stable/c/af38d9a5cb49fe9d0d282b44f17fdc1f3270d99d
- https://git.kernel.org/stable/c/d86c58eb005eb99da402452f3db7a6e0eae32815
- https://git.kernel.org/stable/c/f1216b80c9040a904d2ad7c8cd24ca0ff1f36932
- https://git.kernel.org/stable/c/f86bd16280a0f88b538394e0565c56ce4756da99
Related Security Bulletins
- Exposed IOCTL with Insufficient Access Control in Linux kernel cavium liquidio driver
- Ubuntu update for linux
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-fips
- Ubuntu update for linux-nvidia-tegra
- Ubuntu update for linux-nvidia-6.8
- Ubuntu update for linux-azure
- Ubuntu update for linux
- Ubuntu update for linux-oracle-5.15
- Ubuntu update for linux-xilinx-zynqmp
- Ubuntu update for linux-raspi
- Ubuntu update for linux-gcp-5.15
- Ubuntu update for linux-azure-fips