cbcvebase.
CVE-2026-23179
published 2026-02-14

CVE-2026-23179: In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready() When the socket is closed while in…

PriorityP420high7.8
EPSS
0.17%
6.3th percentile
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready() When the socket is closed while in TCP_LISTEN a callback is run to flush all outstanding packets, which in turns calls nvmet_tcp_listen_data_ready() with the sk_callback_lock held. So we need to check if we are in TCP_LISTEN before attempting to get the sk_callback_lock() to avoid a deadlock.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.10-1 (forky)linux 6.18.10-1 (forky)
linuxlinux
linuxlinux>= 675b453e024154dd547921c6e6d5b58747ba7e0e < 6e0c7503a5803d568d56a9f9bca662cd94a149086e0c7503a5803d568d56a9f9bca662cd94a14908
linuxlinux>= 675b453e024154dd547921c6e6d5b58747ba7e0e < 1c90f930e7b410dd2d75a2a19a85e19c64e98ad51c90f930e7b410dd2d75a2a19a85e19c64e98ad5
linuxlinux>= 675b453e024154dd547921c6e6d5b58747ba7e0e < 2fa8961d3a6a1c2395d8d560ffed2c782681bade2fa8961d3a6a1c2395d8d560ffed2c782681bade
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 6.13.0 < 6.18.106.18.10
linuxlinux_kernel>= 6.7.0 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-ibm
ubuntulinux-ibm-6.8
ubuntulinux-lowlatency
ubuntulinux-lowlatency-hwe-6.8
ubuntulinux-nvidia

CVSS provenance

vendor_ubuntu7.8HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.