cbcvebase.
CVE-2026-23251
published 2026-03-18

CVE-2026-23251: In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfarray and…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.3th percentile
In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfarray and xfblob destructor if we have a valid pointer, and be sure to null out that pointer afterwards. Note that this patch fixes a large number of commits, most of which were merged between 6.9 and 6.10.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.6-1 (forky)linux 6.19.6-1 (forky)
linuxlinux
linuxlinux>= ab97f4b1c030750f2475bf4da8a9554d02206640 < 5de5be3ed7e7fa4ebde4f4b58fb9a629644f92025de5be3ed7e7fa4ebde4f4b58fb9a629644f9202
linuxlinux>= ab97f4b1c030750f2475bf4da8a9554d02206640 < c9ccefacae0d8091683447bc338bd7741417039dc9ccefacae0d8091683447bc338bd7741417039d
linuxlinux>= ab97f4b1c030750f2475bf4da8a9554d02206640 < d827612c81a26cc1dd83a211cfcb5ad8765da0c4d827612c81a26cc1dd83a211cfcb5ad8765da0c4
linuxlinux>= ab97f4b1c030750f2475bf4da8a9554d02206640 < ba408d299a3bb3c5309f40c5326e4fb83ead4247ba408d299a3bb3c5309f40c5326e4fb83ead4247
linuxlinux_kernel>= 0 < 6.19.6-16.19.6-1
linuxlinux_kernel>= 6.10 < 6.12.756.12.75
linuxlinux_kernel>= 6.10.0 < 6.12.756.12.75
linuxlinux_kernel>= 6.13 < 6.18.166.18.16
linuxlinux_kernel>= 6.13.0 < 6.18.166.18.16
linuxlinux_kernel>= 6.19 < 6.19.66.19.6
linuxlinux_kernel>= 6.19.0 < 6.19.66.19.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.