cbcvebase.
CVE-2026-23236
published 2026-03-04

CVE-2026-23236: In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.8th percentile
In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the memory, which can cause problems if invalid data is passed from userspace. Fix this all up by correctly copying the memory before accessing it within the kernel.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 3c8a63e22a0802fd56380f6ab305b419f18eb6f5 < 061cfeb560aa3ddc174153dbe5be9d0b55eb7248061cfeb560aa3ddc174153dbe5be9d0b55eb7248
linuxlinux>= 3c8a63e22a0802fd56380f6ab305b419f18eb6f5 < 6167af934f956d3ae1e06d61f45cd0d1004bbe1a6167af934f956d3ae1e06d61f45cd0d1004bbe1a
linuxlinux>= 3c8a63e22a0802fd56380f6ab305b419f18eb6f5 < a0321e6e58facb39fe191caa0e52ed9aab6a48fea0321e6e58facb39fe191caa0e52ed9aab6a48fe
linuxlinux>= 3c8a63e22a0802fd56380f6ab305b419f18eb6f5 < 0634e8d650993602fc5b389ff7ac525f6542e1410634e8d650993602fc5b389ff7ac525f6542e141
linuxlinux>= 3c8a63e22a0802fd56380f6ab305b419f18eb6f5 < 52917e265aa5f848212f60fc50fc504d8ef1286652917e265aa5f848212f60fc50fc504d8ef12866
linuxlinux>= 3c8a63e22a0802fd56380f6ab305b419f18eb6f5 < 1c008ad0f0d1c1523902b9cdb08e404129677bfc1c008ad0f0d1c1523902b9cdb08e404129677bfc
linuxlinux>= 3c8a63e22a0802fd56380f6ab305b419f18eb6f5 < f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02
linuxlinux>= 3c8a63e22a0802fd56380f6ab305b419f18eb6f5 < 120adae7b42faa641179270c067864544a50ab69120adae7b42faa641179270c067864544a50ab69
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.74-26.12.74-2
linuxlinux_kernel>= 0 < 6.18.13-16.18.13-1
linuxlinux_kernel>= 3.2 < 5.10.2515.10.251
linuxlinux_kernel>= 5.11 < 5.15.2015.15.201
linuxlinux_kernel>= 5.16 < 6.1.1646.1.164
linuxlinux_kernel>= 6.13 < 6.18.136.18.13
linuxlinux_kernel>= 6.19 < 6.19.36.19.3
linuxlinux_kernel>= 6.2 < 6.6.1276.6.127
linuxlinux_kernel>= 6.7 < 6.12.746.12.74
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
ubuntulinux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.