CVE-2026-23251
published 2026-03-18CVE-2026-23251: In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfarray and…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
xfs: only call xf{array,blob}_destroy if we have a valid pointer
Only call the xfarray and xfblob destructor if we have a valid pointer,
and be sure to null out that pointer afterwards. Note that this patch
fixes a large number of commits, most of which were merged between 6.9
and 6.10.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.6-1 (forky) | linux 6.19.6-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= ab97f4b1c030750f2475bf4da8a9554d02206640 < 5de5be3ed7e7fa4ebde4f4b58fb9a629644f9202 | 5de5be3ed7e7fa4ebde4f4b58fb9a629644f9202 |
| linux | linux | >= ab97f4b1c030750f2475bf4da8a9554d02206640 < c9ccefacae0d8091683447bc338bd7741417039d | c9ccefacae0d8091683447bc338bd7741417039d |
| linux | linux | >= ab97f4b1c030750f2475bf4da8a9554d02206640 < d827612c81a26cc1dd83a211cfcb5ad8765da0c4 | d827612c81a26cc1dd83a211cfcb5ad8765da0c4 |
| linux | linux | >= ab97f4b1c030750f2475bf4da8a9554d02206640 < ba408d299a3bb3c5309f40c5326e4fb83ead4247 | ba408d299a3bb3c5309f40c5326e4fb83ead4247 |
| linux | linux_kernel | >= 0 < 6.19.6-1 | 6.19.6-1 |
| linux | linux_kernel | >= 6.10 < 6.12.75 | 6.12.75 |
| linux | linux_kernel | >= 6.10.0 < 6.12.75 | 6.12.75 |
| linux | linux_kernel | >= 6.13 < 6.18.16 | 6.18.16 |
| linux | linux_kernel | >= 6.13.0 < 6.18.16 | 6.18.16 |
| linux | linux_kernel | >= 6.19 < 6.19.6 | 6.19.6 |
| linux | linux_kernel | >= 6.19.0 < 6.19.6 | 6.19.6 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.12.74/6.18.15/6.19.5 xfs null pointer dereference (WID-SEC-2026-0790)
vuldb·2026-05-21·CVSS 5.5
CVE-2026-23251 [MEDIUM] Linux Kernel up to 6.12.74/6.18.15/6.19.5 xfs null pointer dereference (WID-SEC-2026-0790)
A vulnerability was found in Linux Kernel up to 6.12.74/6.18.15/6.19.5. It has been classified as critical. Affected is an unknown function of the component xfs. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2026-23251. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is recommended.
OSV
CVE-2026-23251: In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfa
osv·2026-03-18
CVE-2026-23251 CVE-2026-23251: In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfa
In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfarray and xfblob destructor if we have a valid pointer, and be sure to null out that pointer afterwards. Note that this patch fixes a large number of commits, most of which were merged between 6.9 and 6.10.
GHSA
GHSA-h6jp-94m7-xf6p: In the Linux kernel, the following vulnerability has been resolved:
xfs: only call xf{array,blob}_destroy if we have a valid pointer
Only call the x
ghsa_unreviewed·2026-03-18
CVE-2026-23251 GHSA-h6jp-94m7-xf6p: In the Linux kernel, the following vulnerability has been resolved:
xfs: only call xf{array,blob}_destroy if we have a valid pointer
Only call the x
In the Linux kernel, the following vulnerability has been resolved:
xfs: only call xf{array,blob}_destroy if we have a valid pointer
Only call the xfarray and xfblob destructor if we have a valid pointer,
and be sure to null out that pointer afterwards. Note that this patch
fixes a large number of commits, most of which were merged between 6.9
and 6.10.
OSV
xfs: only call xf{array,blob}_destroy if we have a valid pointer
osv·2026-03-18
CVE-2026-23251 xfs: only call xf{array,blob}_destroy if we have a valid pointer
xfs: only call xf{array,blob}_destroy if we have a valid pointer
In the Linux kernel, the following vulnerability has been resolved:
xfs: only call xf{array,blob}_destroy if we have a valid pointer
Only call the xfarray and xfblob destructor if we have a valid pointer,
and be sure to null out that pointer afterwards. Note that this patch
fixes a large number of commits, most of which were merged between 6.9
and 6.10.
Red Hat
kernel: xfs: only call xf{array,blob}_destroy if we have a valid pointer
vendor_redhat·2026-03-18·CVSS 5.5
CVE-2026-23251 [MEDIUM] CWE-476 kernel: xfs: only call xf{array,blob}_destroy if we have a valid pointer
kernel: xfs: only call xf{array,blob}_destroy if we have a valid pointer
In the Linux kernel, the following vulnerability has been resolved:
xfs: only call xf{array,blob}_destroy if we have a valid pointer
Only call the xfarray and xfblob destructor if we have a valid pointer,
and be sure to null out that pointer afterwards. Note that this patch
fixes a large number of commits, most of which were merged between 6.9
and 6.10.
A NULL pointer dereference vulnerability was found in the Linux kernel's XFS filesystem. The xfarray_destroy() and xfblob_destroy() functions are called without checking if the pointer is valid. When these destructors are invoked on NULL pointers during cleanup paths, a kernel crash occurs. The fix adds NULL checks before calling the destructors and nullifies the poi
Debian
CVE-2026-23251: linux - In the Linux kernel, the following vulnerability has been resolved: xfs: only c...
vendor_debian·2026
CVE-2026-23251 [LOW] CVE-2026-23251: linux - In the Linux kernel, the following vulnerability has been resolved: xfs: only c...
In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfarray and xfblob destructor if we have a valid pointer, and be sure to null out that pointer afterwards. Note that this patch fixes a large number of commits, most of which were merged between 6.9 and 6.10.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.6-1)
sid: resolved (fixed in 6.19.6-1)
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23251 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23251 CVE-2026-23251 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23251 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
xfs: only call xf{array,blob}_destroy if we have a valid pointer
Only call the xfarray and xfblob destructor if we have a valid pointer,
and be sure to null out that pointer afterwards. Note that this patch
fixes a large number of commits, most of which were merged between 6.9
and 6.10.
Source : NVD
Published March 18, 2026
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-uki-virt-addons
kernel-zfcpdump-devel
Bugzilla
CVE-2026-23251 kernel: xfs: only call xf{array,blob}_destroy if we have a valid pointer
bugzilla·2026-03-18·CVSS 5.5
CVE-2026-23251 [MEDIUM] CVE-2026-23251 kernel: xfs: only call xf{array,blob}_destroy if we have a valid pointer
CVE-2026-23251 kernel: xfs: only call xf{array,blob}_destroy if we have a valid pointer
In the Linux kernel, the following vulnerability has been resolved:
xfs: only call xf{array,blob}_destroy if we have a valid pointer
Only call the xfarray and xfblob destructor if we have a valid pointer,
and be sure to null out that pointer afterwards. Note that this patch
fixes a large number of commits, most of which were merged between 6.9
and 6.10.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026031845-CVE-2026-23251-259a@gregkh/T
2026-03-18
Published