Exposed IOCTL with Insufficient Access Control in Linux kernel - CVE-2026-23256
Published: March 20, 2026
Vulnerability details
The vulnerability allows a local user to cause a memory leak.
The vulnerability exists due to an off-by-one error in the VF setup_nic_devices() cleanup function in the net: liquidio component when initializing network devices. A local user can trigger a failure during device setup to cause a memory leak.
The vulnerability specifically affects the cleanup logic in setup_nic_devices() where the loop fails to release memory for the current index on error path. This requires the ability to configure or trigger virtual function (VF) device initialization, typically available to privileged users.
Affected software
Ubuntu
linux (Ubuntu package)
linux-xilinx-zynqmp (Ubuntu package)
linux-raspi (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-fips (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
How to mitigate CVE-2026-23256
linux (Ubuntu package) - addressed in versions 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-117.117, 6.8.0-117.117.1, 6.8.0-117.117.1~22.04.1, 6.8.0-1041.44, 6.8.0-1054.60, 6.8.0-1055.56, 6.8.0-1055.56~22.04.1, 6.8.0-1055.58+fips1, 6.8.0-1056.60, 6.8.0-1058.61, 6.8.0-1058.61+fips1, 6.8.0-2045.46, 6.8.1-1051.52, 6.8.1-1051.52~22.04.1
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-raspi (Ubuntu package) - addressed in versions 5.15.0.1105.103, 5.15.0-1105.108
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1
linux-fips (Ubuntu package) - update to 6.8.0-116.116+fips1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1024.24
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1054.57, 6.8.0-1054.57.1
linux-nvidia-6.8 (Ubuntu package) - update to 6.8.0-1054.57~22.04.1
linux-azure (Ubuntu package) - update to 6.8.0-1056.62
External References
- https://git.kernel.org/stable/c/01fbca1e93ec3f39f76c31a8f9afa32ce00da48a
- https://git.kernel.org/stable/c/3bf519e39b51cb08a93c0599870b35a23db1031e
- https://git.kernel.org/stable/c/4640fa5ad5e1a0dbd1c2d22323b7d70a8107dcfd
- https://git.kernel.org/stable/c/52b19b3a22306fe452ec9e8ff96063f4bfb77b99
- https://git.kernel.org/stable/c/6cbba46934aefdfb5d171e0a95aec06c24f7ca30
- https://git.kernel.org/stable/c/71a56b89203ec7e5670d94a61a9b4ae617eca804
- https://git.kernel.org/stable/c/bd680e56e316be92c01568be98d85d7a6c9bd92c
Related Security Bulletins
- Exposed IOCTL with Insufficient Access Control in Linux kernel cavium liquidio driver
- Ubuntu update for linux
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-fips
- Ubuntu update for linux-nvidia-tegra
- Ubuntu update for linux-nvidia-6.8
- Ubuntu update for linux-azure
- Ubuntu update for linux
- Ubuntu update for linux-oracle-5.15
- Ubuntu update for linux-xilinx-zynqmp
- Ubuntu update for linux-raspi
- Ubuntu update for linux-gcp-5.15
- Ubuntu update for linux-azure-fips