cbcvebase.
CVE-2026-23096
published 2026-02-04

CVE-2026-23096: In the Linux kernel, the following vulnerability has been resolved: uacce: fix cdev handling in the cleanup path When cdev_device_add fails, it internally…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: uacce: fix cdev handling in the cleanup path When cdev_device_add fails, it internally releases the cdev memory, and if cdev_device_del is then executed, it will cause a hang error. To fix it, we check the return value of cdev_device_add() and clear uacce->cdev to avoid calling cdev_device_del in the uacce_remove.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 015d239ac0142ad0e26567fd890ef8d171f13709 < c94c7188d325bc5137d447d67a2f18f7d4f2f4a3c94c7188d325bc5137d447d67a2f18f7d4f2f4a3
linuxlinux>= 015d239ac0142ad0e26567fd890ef8d171f13709 < 1bc3e51367c420e6db31f41efa874c7a8e12194a1bc3e51367c420e6db31f41efa874c7a8e12194a
linuxlinux>= 015d239ac0142ad0e26567fd890ef8d171f13709 < 819d647406200d0e83e56fd2df8f451b11290559819d647406200d0e83e56fd2df8f451b11290559
linuxlinux>= 015d239ac0142ad0e26567fd890ef8d171f13709 < d9031575a2f8aabc53af3025dd79af313a2e046bd9031575a2f8aabc53af3025dd79af313a2e046b
linuxlinux>= 015d239ac0142ad0e26567fd890ef8d171f13709 < 98d67a1bd6caddd0a8b8c82a0b925742cf50093698d67a1bd6caddd0a8b8c82a0b925742cf500936
linuxlinux>= 015d239ac0142ad0e26567fd890ef8d171f13709 < bd2393ed7712513e7e2dbcb6e21464a67ff9e702bd2393ed7712513e7e2dbcb6e21464a67ff9e702
linuxlinux>= 015d239ac0142ad0e26567fd890ef8d171f13709 < a3bece3678f6c88db1f44c602b2a63e84b4040aca3bece3678f6c88db1f44c602b2a63e84b4040ac
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 5.11 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1626.1.162
linuxlinux_kernel>= 5.7 < 5.10.2495.10.249
linuxlinux_kernel>= 6.13 < 6.18.86.18.8
linuxlinux_kernel>= 6.2 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7 < 6.12.686.12.68
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.