cbcvebase.
CVE-2026-23296
published 2026-03-25

CVE-2026-23296: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix refcount leak for tagset_refcnt This leak will cause a hang when tearing…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix refcount leak for tagset_refcnt This leak will cause a hang when tearing down the SCSI host. For example, iscsid hangs with the following call trace: [130120.652718] scsi_alloc_sdev: Allocation failure during SCSI scanning, some SCSI devices might not be configured PID: 2528 TASK: ffff9d0408974e00 CPU: 3 COMMAND: "iscsid" #0 [ffffb5b9c134b9e0] __schedule at ffffffff860657d4 #1 [ffffb5b9c134ba28] schedule at ffffffff86065c6f #2 [ffffb5b9c134ba40] schedule_timeout at ffffffff86069fb0 #3 [ffffb5b9c134bab0] __wait_for_common at ffffffff8606674f #4 [ffffb5b9c134bb10] scsi_remove_host at ffffffff85bfe84b #5 [ffffb5b9c134bb30] iscsi_sw_tcp_session_destroy at ffffffffc03031c4 [iscsi_tcp] #6 [ffffb5b9c134bb48] iscsi_if_recv_msg at ffffffffc0292692 [scsi_transport_iscsi] #7 [ffffb5b9c134bb98] iscsi_if_rx at ffffffffc02929c2 [scsi_transport_iscsi] #8 [ffffb5b9c134bbf0] netlink_unicast at ffffffff85e551d6 #9 [ffffb5b9c134bc38] netlink_sendmsg at ffffffff85e554ef

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.223 < 5.115.11
linuxlinux>= 5.15.164 < 5.15.2035.15.203
linuxlinux>= 5.19.12 < 5.205.20
linuxlinux>= 8fe4ce5836e932f5766317cb651c1ff2a4cd0506 < 9f5e4abed9248448aa1b45b12ab0bea4d329b56a9f5e4abed9248448aa1b45b12ab0bea4d329b56a
linuxlinux>= 8fe4ce5836e932f5766317cb651c1ff2a4cd0506 < 7c01b680beaf4d3143866b062b8e770e8b237fb87c01b680beaf4d3143866b062b8e770e8b237fb8
linuxlinux>= 8fe4ce5836e932f5766317cb651c1ff2a4cd0506 < ec5c17c687b189dbc09dfdec11b669caa40bc395ec5c17c687b189dbc09dfdec11b669caa40bc395
linuxlinux>= 8fe4ce5836e932f5766317cb651c1ff2a4cd0506 < 944a333c8e4d42256556c1d2ebb6d773a33e0dcd944a333c8e4d42256556c1d2ebb6d773a33e0dcd
linuxlinux>= 8fe4ce5836e932f5766317cb651c1ff2a4cd0506 < a03d96598d39fdf605d90731db3ef3b13fb8bdc8a03d96598d39fdf605d90731db3ef3b13fb8bdc8
linuxlinux>= 8fe4ce5836e932f5766317cb651c1ff2a4cd0506 < 1ac22c8eae81366101597d48360718dff9b9d9801ac22c8eae81366101597d48360718dff9b9d980
linuxlinux>= f818708eeeae793e12dc39f8984ed7732048a7d9 < 0e274674714427dc578bb99db5b86e312d2b57f80e274674714427dc578bb99db5b86e312d2b57f8
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 5.10.223 < 5.115.11
linuxlinux_kernel>= 5.15.164 < 5.15.2035.15.203
linuxlinux_kernel>= 5.19.12 < 6.06.0
linuxlinux_kernel>= 6.0.0 < 6.1.1676.1.167
linuxlinux_kernel>= 6.0.1 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_msrc7.1HIGH
vendor_ubuntu7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.