PT-2026-27739 · Linux · Linux Kernel

Published

2026-01-01

·

Updated

2026-05-22

·

CVE-2026-23374

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.0-rc1lblk+ #84
Description The Linux kernel's blktrace component contains an issue where this cpu read() and this cpu write() are used in a preemptible context. Specifically, tracing record cmdline() utilizes these functions on the per-CPU variable trace cmdline save, but does not ensure preemption is disabled. This occurs when calling tracing record cmdline(current) early in the blk tracer path, before ring buffer reservation. This can lead to a kernel bug, as observed in testing with blktrace/002, resulting in a crash. The issue affects multiple paths including blk add trace plug(), blk add trace unplug(), and blk add trace rq().
Recommendations Update to a version of the Linux kernel that addresses this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2026-23374
ECHO-B1E9-58AF-CBE9
OESA-2026-2418
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1

Affected Products

Linux Kernel