Empty Exception Block in Linux kernel - CVE-2026-23295

 

Empty Exception Block in Linux kernel - CVE-2026-23295

Published: March 25, 2026


Vulnerability identifier: #VU124573
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23295
CWE-ID: CWE-1069
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a deadlock condition in the AMDXDNA driver when handling IOCTL queries during device suspend and resume operations. A local user can issue a specially crafted IOCTL request during an auto-suspend cycle to trigger a deadlock, resulting in a denial of service.

The system must be in the process of suspending or resuming, and the attacker must have access to the device interface.


Affected software

Linux kernel

How to mitigate CVE-2026-23295

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins