CVE-2026-23087 — Missing Release of Memory after Effective Lifetime in Linux
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateApr 16
Description
In the Linux kernel, the following vulnerability has been resolved:
scsi: xen: scsiback: Fix potential memory leak in scsiback_remove()
Memory allocated for struct vscsiblk_info in scsiback_probe() is not
freed in scsiback_remove() leading to potential memory leaks on remove,
as well as in the scsiback_probe() error paths. Fix that by freeing it
in scsiback_remove().
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages3 packages
▶CVEListV5linux/linuxd9d660f6e562a47b4065eeb7e538910b0471b988 — a8bb3ec8d85951a56af0a72d93ccbc2aee42eef9+7
Patches
🔴Vulnerability Details
3OSV▶
CVE-2026-23087: In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Fix potential memory leak in scsiback_remove() Memory allocat↗2026-02-04
GHSA▶
GHSA-pm73-pr98-fpfg: In the Linux kernel, the following vulnerability has been resolved:
scsi: xen: scsiback: Fix potential memory leak in scsiback_remove()
Memory alloc↗2026-02-04
📋Vendor Advisories
4Debian▶
CVE-2026-23087: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: xen: ...↗2026