Race condition in Linux kernel - CVE-2026-23469

 

Race condition in Linux kernel - CVE-2026-23469

Published: April 6, 2026


Vulnerability identifier: #VU124901
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23469
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to a race condition in the drm/imagination GPU driver interrupt handling during runtime power management suspend when suspending the GPU while an IRQ handler is still running on another CPU core. A local attacker can trigger GPU activity that races with runtime suspend to cause a denial of service.

This issue can lead to kernel crashes or a kernel panic when the IRQ handler accesses GPU registers while the GPU is suspended.


Affected software

Linux kernel
Debian Linux
Ubuntu
linux (Ubuntu package)
linux (Debian package)

How to mitigate CVE-2026-23469

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 6.8.0-139.139+fips1, 6.8.0-1049.53, 6.8.0-1062.65+fips1, 6.8.0-1062.65.1, 6.8.0-1062.65~22.04.1, 6.8.0-1062.70, 6.8.0-1064.68, 6.8.0-1067.75, 6.8.0-1067.75+fips1, 6.8.1-1059.60, 6.8.1-1059.60~22.04.1
linux (Debian package) - update to 6.12.94-1

External References

Related Security Bulletins