CVE-2026-23376Missing Lock Check in Linux

CWE-414Missing Lock Check7 documents6 sources
Severity
3.3LOW
No vector
EPSS
0.0%
top 94.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25

Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-fcloop: Check remoteport port_state before calling done callback In nvme_fc_handle_ls_rqst_work, the lsrsp->done callback is only set when remoteport->port_state is FC_OBJSTATE_ONLINE. Otherwise, the nvme_fc_xmt_ls_rsp's LLDD call to lport->ops->xmt_ls_rsp is expected to fail and the nvme-fc transport layer itself will directly call nvme_fc_xmt_ls_rsp_free instead of relying on LLDD's done callback to free the lsrsp reso

Affected Packages4 packages

Linuxlinux/linux_kernel6.18.06.18.17+1
Debianlinux/linux_kernel< 6.19.8-1
CVEListV5linux/linux10c165af35d225eb033f4edc7fcc699a8d2d533df30b95159a53e72529a9ca1667f11cd1970240a7+4
debiandebian/linux< linux 6.19.8-1 (forky)

🔴Vulnerability Details

3
OSV
CVE-2026-23376: In the Linux kernel, the following vulnerability has been resolved: nvmet-fcloop: Check remoteport port_state before calling done callback In nvme_fc_2026-03-25
GHSA
GHSA-36q5-3685-99hr: In the Linux kernel, the following vulnerability has been resolved: nvmet-fcloop: Check remoteport port_state before calling done callback In nvme_f2026-03-25
OSV
nvmet-fcloop: Check remoteport port_state before calling done callback2026-03-25

📋Vendor Advisories

2
Red Hat
kernel: nvmet-fcloop: Check remoteport port_state before calling done callback2026-03-25
Debian
CVE-2026-23376: linux - In the Linux kernel, the following vulnerability has been resolved: nvmet-fcloo...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23376 Impact, Exploitability, and Mitigation Steps | Wiz