cbcvebase.
CVE-2026-23187
published 2026-02-14

CVE-2026-23187: In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains Fix out-of-range access of…

PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains Fix out-of-range access of bc->domains in imx8m_blk_ctrl_remove().

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 2684ac05a8c4d2d5c49e6c11eb6206b30a284813 < 7842b5dfcac888ece025a2321257d74b2264b0997842b5dfcac888ece025a2321257d74b2264b099
linuxlinux>= 2684ac05a8c4d2d5c49e6c11eb6206b30a284813 < 071159ff5c0bf2e5efff79501e23faf3775cbcd1071159ff5c0bf2e5efff79501e23faf3775cbcd1
linuxlinux>= 2684ac05a8c4d2d5c49e6c11eb6206b30a284813 < 4390dcdabb5fca4647bf56a5a6b050bbdfa5760f4390dcdabb5fca4647bf56a5a6b050bbdfa5760f
linuxlinux>= 2684ac05a8c4d2d5c49e6c11eb6206b30a284813 < eb54ce033b344b531b374496e68a2554b2b56b5aeb54ce033b344b531b374496e68a2554b2b56b5a
linuxlinux>= 2684ac05a8c4d2d5c49e6c11eb6206b30a284813 < 6bd8b4a92a901fae1a422e6f914801063c345e8d6bd8b4a92a901fae1a422e6f914801063c345e8d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 5.16 < 6.1.1636.1.163
linuxlinux_kernel>= 6.13 < 6.18.106.18.10
linuxlinux_kernel>= 6.2 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-fips

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.