cbcvebase.
CVE-2026-23259
published 2026-03-18

CVE-2026-23259: In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write request…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.10%
1.0th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write request goes through io_req_rw_cleanup() and has an allocated iovec attached and fails to put to the rw_cache, then it may end up with an unaccounted iovec pointer. Have io_rw_recycle() return whether it recycled the request or not, and use that to gauge whether to free a potential iovec or not.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.10-1 (forky)linux 6.18.10-1 (forky)
linuxlinux
linuxlinux>= a9165b83c1937eeed1f0c731468216d6371d647f < 1d5f2329ab4df65c2ee011b986d8a6e05ad0f67c1d5f2329ab4df65c2ee011b986d8a6e05ad0f67c
linuxlinux>= a9165b83c1937eeed1f0c731468216d6371d647f < 4b9748055457ac3a0710bf210c229d01ea1b01b94b9748055457ac3a0710bf210c229d01ea1b01b9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 6.10 < 6.18.106.18.10
linuxlinux_kernel>= 6.10.0 < 6.18.106.18.10
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.