CVE-2026-23110Race Condition in Linux

Severity
4.7MEDIUMNVD
EPSS
0.0%
top 97.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateFeb 10

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final completions race against each other The fragile ordering between marking commands completed or failed so that the error handler only wakes when the last running command completes or times out has race conditions. These race conditions can cause the SCSI layer to fail to wake the error handler, leaving I/O through the SCSI host stuck as the error state cannot advance. First, the

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages7 packages

NVDlinux/linux_kernel5.55.10.249+5
Debianlinux/linux_kernel< 5.10.249-1+3
CVEListV5linux/linux6eb045e092efefafc6687409a6fa6d1dabf0fb69cc872e35c0df80062abc71268d690a2f749e542e+6
debiandebian/linux< linux 6.1.162-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.162-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2026-23110: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final completions race against each oth2026-02-04
GHSA
GHSA-7p3h-gfr2-rwcv: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final completions race against each ot2026-02-04

📋Vendor Advisories

3
Microsoft
scsi: core: Wake up the error handler when final completions race against each other2026-02-10
Red Hat
kernel: scsi: core: Wake up the error handler when final completions race against each other2026-02-04
Debian
CVE-2026-23110: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: core:...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23110 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23110 — Race Condition in Linux | cvebase