CVE-2026-23259
published 2026-03-18CVE-2026-23259: In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write request…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.10%
1.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: free potentially allocated iovec on cache put failure
If a read/write request goes through io_req_rw_cleanup() and has an
allocated iovec attached and fails to put to the rw_cache, then it may
end up with an unaccounted iovec pointer. Have io_rw_recycle() return
whether it recycled the request or not, and use that to gauge whether to
free a potential iovec or not.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.10-1 (forky) | linux 6.18.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= a9165b83c1937eeed1f0c731468216d6371d647f < 1d5f2329ab4df65c2ee011b986d8a6e05ad0f67c | 1d5f2329ab4df65c2ee011b986d8a6e05ad0f67c |
| linux | linux | >= a9165b83c1937eeed1f0c731468216d6371d647f < 4b9748055457ac3a0710bf210c229d01ea1b01b9 | 4b9748055457ac3a0710bf210c229d01ea1b01b9 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.18.10-1 | 6.18.10-1 |
| linux | linux_kernel | >= 6.10 < 6.18.10 | 6.18.10 |
| linux | linux_kernel | >= 6.10.0 < 6.18.10 | 6.18.10 |
| msrc | azl3_kernel_6.6.126.1-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: io_uring/rw: free potentially allocated iovec on cache put failure
vendor_redhat·2026-03-18·CVSS 5.5
CVE-2026-23259 [LOW] kernel: io_uring/rw: free potentially allocated iovec on cache put failure
kernel: io_uring/rw: free potentially allocated iovec on cache put failure
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: free potentially allocated iovec on cache put failure
If a read/write request goes through io_req_rw_cleanup() and has an
allocated iovec attached and fails to put to the rw_cache, then it may
end up with an unaccounted iovec pointer. Have io_rw_recycle() return
whether it recycled the request or not, and use that to gauge whether to
free a potential iovec or not.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat En
Microsoft
io_uring/rw: free potentially allocated iovec on cache put failure
vendor_msrc·2026-03-10·CVSS 5.5
CVE-2026-23259 [MEDIUM] io_uring/rw: free potentially allocated iovec on cache put failure
io_uring/rw: free potentially allocated iovec on cache put failure
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-23259: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring/rw...
vendor_debian·2026
CVE-2026-23259 [LOW] CVE-2026-23259: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring/rw...
In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write request goes through io_req_rw_cleanup() and has an allocated iovec attached and fails to put to the rw_cache, then it may end up with an unaccounted iovec pointer. Have io_rw_recycle() return whether it recycled the request or not, and use that to gauge whether to free a potential iovec or not.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.18.10-1)
sid: resolved (fixed in 6.18.10-1)
trixie: open
VulDB
Linux Kernel up to 6.18.9 io_uring io_req_rw_cleanup allocation of resources (WID-SEC-2026-0790)
vuldb·2026-06-01·CVSS 5.5
CVE-2026-23259 [MEDIUM] Linux Kernel up to 6.18.9 io_uring io_req_rw_cleanup allocation of resources (WID-SEC-2026-0790)
A vulnerability was found in Linux Kernel up to 6.18.9. It has been classified as critical. This affects the function io_req_rw_cleanup of the component io_uring. Performing a manipulation results in allocation of resources.
This vulnerability was named CVE-2026-23259. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
GHSA-q3hj-qw3j-gv7p: In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: free potentially allocated iovec on cache put failure
If a read/wri
ghsa_unreviewed·2026-03-18
CVE-2026-23259 GHSA-q3hj-qw3j-gv7p: In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: free potentially allocated iovec on cache put failure
If a read/wri
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: free potentially allocated iovec on cache put failure
If a read/write request goes through io_req_rw_cleanup() and has an
allocated iovec attached and fails to put to the rw_cache, then it may
end up with an unaccounted iovec pointer. Have io_rw_recycle() return
whether it recycled the request or not, and use that to gauge whether to
free a potential iovec or not.
OSV
io_uring/rw: free potentially allocated iovec on cache put failure
osv·2026-03-18
CVE-2026-23259 io_uring/rw: free potentially allocated iovec on cache put failure
io_uring/rw: free potentially allocated iovec on cache put failure
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: free potentially allocated iovec on cache put failure
If a read/write request goes through io_req_rw_cleanup() and has an
allocated iovec attached and fails to put to the rw_cache, then it may
end up with an unaccounted iovec pointer. Have io_rw_recycle() return
whether it recycled the request or not, and use that to gauge whether to
free a potential iovec or not.
OSV
CVE-2026-23259: In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write
osv·2026-03-18
CVE-2026-23259 CVE-2026-23259: In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write
In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write request goes through io_req_rw_cleanup() and has an allocated iovec attached and fails to put to the rw_cache, then it may end up with an unaccounted iovec pointer. Have io_rw_recycle() return whether it recycled the request or not, and use that to gauge whether to free a potential iovec or not.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-23259 kernel: io_uring/rw: free potentially allocated iovec on cache put failure
bugzilla·2026-03-18·CVSS 5.5
CVE-2026-23259 [MEDIUM] CVE-2026-23259 kernel: io_uring/rw: free potentially allocated iovec on cache put failure
CVE-2026-23259 kernel: io_uring/rw: free potentially allocated iovec on cache put failure
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: free potentially allocated iovec on cache put failure
If a read/write request goes through io_req_rw_cleanup() and has an
allocated iovec attached and fails to put to the rw_cache, then it may
end up with an unaccounted iovec pointer. Have io_rw_recycle() return
whether it recycled the request or not, and use that to gauge whether to
free a potential iovec or not.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026031819-CVE-2026-23259-5bd7@gregkh/T
Wiz
CVE-2026-23259 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-23259 CVE-2026-23259 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23259 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
io_uring/rw: free potentially allocated iovec on cache put failure
If a read/write request goes through io_req_rw_cleanup() and has an
allocated iovec attached and fails to put to the rw_cache, then it may
end up with an unaccounted iovec pointer. Have io_rw_recycle() return
whether it recycled the request or not, and use that to gauge whether to
free a potential iovec or not.
Source : NVD
## 5.5
Score
Published March 18, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (E
2026-03-18
Published