cbcvebase.
CVE-2026-23344
published 2026-03-25

CVE-2026-23344: In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix use-after-free on error path In the error path of sev_tsm_init_locked()…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix use-after-free on error path In the error path of sev_tsm_init_locked(), the code dereferences 't' after it has been freed with kfree(). The pr_err() statement attempts to access t->tio_en and t->tio_init_done after the memory has been released. Move the pr_err() call before kfree(t) to access the fields while the memory is still valid. This issue reported by Smatch static analyser

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 4be423572da1f4c11f45168e3fafda870ddac9f8 < 79a26fe3175b9ed7c0c9541b197cb9786237c0f779a26fe3175b9ed7c0c9541b197cb9786237c0f7
linuxlinux>= 4be423572da1f4c11f45168e3fafda870ddac9f8 < 889b0e2721e793eb46cf7d17b965aa3252af3ec8889b0e2721e793eb46cf7d17b965aa3252af3ec8
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.1 < 6.19.76.19.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.