PT-2026-27692 · Linux · Linux Kernel
Published
2026-01-01
·
Updated
2026-04-20
·
CVE-2026-23327
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.19.0
Description
The Linux kernel contains a flaw in the cxl/mbox subsystem. Specifically, the
cxl payload from user allowed() function casts and dereferences input payload data without first verifying its size. This can lead to a read-access violation when a raw mailbox command is sent with an undersized payload, such as a 1-byte payload for an operation expecting a 16-byte UUID. This results in reading past the allocated buffer, triggering a kernel memory safety issue.Recommendations
Update to Linux kernel version 6.19.0 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel