CVE-2026-23199

CWE-667CWE-8337 documents7 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 97.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14

Description

In the Linux kernel, the following vulnerability has been resolved: procfs: avoid fetching build ID while holding VMA lock Fix PROCMAP_QUERY to fetch optional build ID only after dropping mmap_lock or per-VMA lock, whichever was used to lock VMA under question, to avoid deadlock reported by syzbot: -> #1 (&mm->mmap_lock){++++}-{4:4}: __might_fault+0xed/0x170 _copy_to_iter+0x118/0x1720 copy_page_to_iter+0x12d/0x1e0 filemap_read+0x720/0x10a0 blkdev_read_iter+0x2b5/0x4e0 vfs_read+0x7f4/0xae0 ksy

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel6.116.12.70+2
CVEListV5linux/linuxed5d583a88a9207b866c14ba834984c6f3c51d23b9b97e6aeb534315f9646b2090d1a5024c6a4e82+3
Debianlinux< 6.12.73-1+1

Patches

🔴Vulnerability Details

3
OSV
CVE-2026-23199: In the Linux kernel, the following vulnerability has been resolved: procfs: avoid fetching build ID while holding VMA lock Fix PROCMAP_QUERY to fetch2026-02-14
CVEList
procfs: avoid fetching build ID while holding VMA lock2026-02-14
GHSA
GHSA-hjgx-24cq-764x: In the Linux kernel, the following vulnerability has been resolved: procfs: avoid fetching build ID while holding VMA lock Fix PROCMAP_QUERY to fetc2026-02-14

📋Vendor Advisories

2
Red Hat
kernel: procfs: avoid fetching build ID while holding VMA lock2026-02-14
Debian
CVE-2026-23199: linux - In the Linux kernel, the following vulnerability has been resolved: procfs: avo...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23199 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23199 (MEDIUM CVSS 5.5) | In the Linux kernel | cvebase.io