cbcvebase.
CVE-2026-23123
published 2026-02-14

CVE-2026-23123: In the Linux kernel, the following vulnerability has been resolved: interconnect: debugfs: initialize src_node and dst_node to empty strings The…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.0th percentile
In the Linux kernel, the following vulnerability has been resolved: interconnect: debugfs: initialize src_node and dst_node to empty strings The debugfs_create_str() API assumes that the string pointer is either NULL or points to valid kmalloc() memory. Leaving the pointer uninitialized can cause problems. Initialize src_node and dst_node to empty strings before creating the debugfs entries to guarantee that reads and writes are safe.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux
linuxlinux>= 770c69f037c18cfaa37c3d6c6ef8bd257635513f < aa79a5a959c7c414bd6fba01ea8dbaddd44f13e7aa79a5a959c7c414bd6fba01ea8dbaddd44f13e7
linuxlinux>= 770c69f037c18cfaa37c3d6c6ef8bd257635513f < 935d0938b570589c8b0a1733d2cba3c39d027f25935d0938b570589c8b0a1733d2cba3c39d027f25
linuxlinux>= 770c69f037c18cfaa37c3d6c6ef8bd257635513f < 5d7c7e1fb3ec24fdd0f9faa27b666d6789e891e85d7c7e1fb3ec24fdd0f9faa27b666d6789e891e8
linuxlinux>= 770c69f037c18cfaa37c3d6c6ef8bd257635513f < 8cc27f5c6dd17dd090f3a696683f04336c162ff58cc27f5c6dd17dd090f3a696683f04336c162ff5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 6.13 < 6.18.86.18.8
linuxlinux_kernel>= 6.6 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7 < 6.12.686.12.68
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fde-6.17
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.17
ubuntulinux-gcp-fips
ubuntulinux-gke

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.