cbcvebase.
CVE-2026-23101
published 2026-02-04

CVE-2026-23101: In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it is fully ready Before this change the…

PriorityP417medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.12%
2.1th percentile
In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it is fully ready Before this change the LED was added to leds_list before led_init_core() gets called adding it the list before led_classdev.set_brightness_work gets initialized. This leaves a window where led_trigger_register() of a LED's default trigger will call led_trigger_set() which calls led_set_brightness() which in turn will end up queueing the *uninitialized* led_classdev.set_brightness_work. This race gets hit by the lenovo-thinkpad-t14s EC driver which registers 2 LEDs with a default trigger provided by snd_ctl_led.ko in quick succession. The first led_classdev_register() causes an async modprobe of snd_ctl_led to run and that async modprobe manages to exactly hit the window where the second LED is on the leds_list without led_init_core() being called for it, resulting in: ------------[ cut here ]------------ WARNING: CPU: 11 PID: 5608 at kernel/workqueue.c:4234 __flush_work+0x344/0x390 Hardware name: LENOVO 21N2S01F0B/21N2S01F0B, BIOS N42ET93W (2.23 ) 09/01/2025 ... Call trace: __flush_work+0x344/0x390 (P) flush_work+0x2c/0x50 led_trigger_set+0x1c8/0x340 led_trigger_register+0x17c/0x1c0 led_trigger_register_simple+0x84/0xe8 snd_ctl_led_init+0x40/0xf88 [snd_ctl_led] do_one_initcall+0x5c/0x318 do_init_module+0x9c/0x2b8 load_module+0x7e0/0x998 Close the race window by moving the adding of the LED to leds_list to after the led_init_core() call.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= d23a22a74fded23a12434c9463fe66cec2b0afcd < f7a6df659af777058833802c29b3b7974db5e78af7a6df659af777058833802c29b3b7974db5e78a
linuxlinux>= d23a22a74fded23a12434c9463fe66cec2b0afcd < d117fdcb21b05c0e0460261d017b92303cd9ba77d117fdcb21b05c0e0460261d017b92303cd9ba77
linuxlinux>= d23a22a74fded23a12434c9463fe66cec2b0afcd < e90c861411fc84629a240384b0a72830539d3386e90c861411fc84629a240384b0a72830539d3386
linuxlinux>= d23a22a74fded23a12434c9463fe66cec2b0afcd < 2757f7748ce2d0fa44112024907bafb37e104d6e2757f7748ce2d0fa44112024907bafb37e104d6e
linuxlinux>= d23a22a74fded23a12434c9463fe66cec2b0afcd < da565bf98c9ad0eabcb09fc97859e0b52f98b7c3da565bf98c9ad0eabcb09fc97859e0b52f98b7c3
linuxlinux>= d23a22a74fded23a12434c9463fe66cec2b0afcd < 78822628165f3d817382f67f91129161159ca23478822628165f3d817382f67f91129161159ca234
linuxlinux>= d23a22a74fded23a12434c9463fe66cec2b0afcd < d1883cefd31752f0504b94c3bcfa1f6d511d6e87d1883cefd31752f0504b94c3bcfa1f6d511d6e87
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 3.7 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.86.18.8
linuxlinux_kernel>= 6.2 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7 < 6.12.686.12.68
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.