cbcvebase.
CVE-2026-23229
published 2026-02-18

CVE-2026-23229: In the Linux kernel, the following vulnerability has been resolved: crypto: virtio - Add spinlock protection with virtqueue notification When VM boots with one…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.3th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: virtio - Add spinlock protection with virtqueue notification When VM boots with one virtio-crypto PCI device and builtin backend, run openssl benchmark command with multiple processes, such as openssl speed -evp aes-128-cbc -engine afalg -seconds 10 -multi 32 openssl processes will hangup and there is error reported like this: virtio_crypto virtio0: dataq.0:id 3 is not a head! It seems that the data virtqueue need protection when it is handled for virtio done notification. If the spinlock protection is added in virtcrypto_done_task(), openssl benchmark with multiple processes works well.

Affected

78 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0eb69890e86775d178452880ea0d24384c5ccedf < 552475d0b6cece73a52c0fa5faa0ce45e99df74b552475d0b6cece73a52c0fa5faa0ce45e99df74b
linuxlinux>= 4.19.306 < 4.204.20
linuxlinux>= 5.10.209 < 5.10.2515.10.251
linuxlinux>= 5.15.148 < 5.15.2015.15.201
linuxlinux>= 5.4.268 < 5.55.5
linuxlinux>= 6.1.75 < 6.1.1646.1.164
linuxlinux>= 6.6.14 < 6.6.1256.6.125
linuxlinux>= 6.7.2 < 6.86.8
linuxlinux>= 75cba72ddb788a5b9c7ed2139fbb84383df029eb < 8ee8ccfd60bf17cbdab91069d324b5302f4f3a308ee8ccfd60bf17cbdab91069d324b5302f4f3a30
linuxlinux>= ae4747dab2eab95a68bb2f6c7e904bff0424e1b1 < c9e594194795c86ca753ad6ed64c2762e9309d0dc9e594194795c86ca753ad6ed64c2762e9309d0d
linuxlinux>= c4c54fce9ec54a59a4ca035af13c2823c76684cc < d6f0d586808689963e58fd739bed626ff5013b24d6f0d586808689963e58fd739bed626ff5013b24
linuxlinux>= fed93fb62e05c38152b0fc1dc9609639e63eed76 < c0a0ded3bb7fd45f720faa48449a930153257d3ac0a0ded3bb7fd45f720faa48449a930153257d3a
linuxlinux>= fed93fb62e05c38152b0fc1dc9609639e63eed76 < e69a7b0a71b6561b3b6459f1fded8d589f2e8ac2e69a7b0a71b6561b3b6459f1fded8d589f2e8ac2
linuxlinux>= fed93fb62e05c38152b0fc1dc9609639e63eed76 < 49c57c6c108931a914ed94e3c0ddb974008260a349c57c6c108931a914ed94e3c0ddb974008260a3
linuxlinux>= fed93fb62e05c38152b0fc1dc9609639e63eed76 < b505047ffc8057555900d2d3a005d033e6967382b505047ffc8057555900d2d3a005d033e6967382
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.12-16.18.12-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_msrc7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.