Resource exhaustion in Linux kernel - CVE-2026-23244

 

Resource exhaustion in Linux kernel - CVE-2026-23244

Published: March 20, 2026


Vulnerability identifier: #VU124205
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23244
CWE-ID: CWE-400
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the nvme_pr_read_keys() function when processing a user-provided num_keys value. A local user can send a specially crafted request with a large num_keys value to cause excessive memory allocation attempts, leading to a denial of service.

Exploitation requires local system access and the ability to invoke NVMe ioctl commands. No authentication beyond standard system access is required.


Affected software

Linux kernel
Debian Linux
Ubuntu
openEuler
kernel
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
bpftool
kernel-source
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)
linux (Debian package)

How to mitigate CVE-2026-23244

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
kernel - update to 6.6.0-145.1.14.152
python3-perf-debuginfo - update to 6.6.0-145.1.14.152
python3-perf - update to 6.6.0-145.1.14.152
perf-debuginfo - update to 6.6.0-145.1.14.152
perf - update to 6.6.0-145.1.14.152
kernel-tools-devel - update to 6.6.0-145.1.14.152
kernel-tools-debuginfo - update to 6.6.0-145.1.14.152
kernel-tools - update to 6.6.0-145.1.14.152
kernel-headers - update to 6.6.0-145.1.14.152
kernel-devel - update to 6.6.0-145.1.14.152
kernel-debugsource - update to 6.6.0-145.1.14.152
kernel-debuginfo - update to 6.6.0-145.1.14.152
bpftool-debuginfo - update to 6.6.0-145.1.14.152
bpftool - update to 6.6.0-145.1.14.152
kernel-source - update to 6.6.0-145.1.14.152
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - update to 6.8.0-1061.64+1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1
linux (Debian package) - update to 6.12.85-1

External References

Related Security Bulletins