PT-2026-8121 · Linux+3 · Linux Kernel+3

CVE-2026-23128

·

Published

2026-01-01

·

Updated

2026-07-28

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions prior to 6.6.98-android15-8-g0b1d2aee7fc3
Description The Linux kernel contains a flaw in the arm64 architecture related to Control Flow Integrity (CFI). A Data Abort (DABT) can occur on Android-based systems during resume from hibernation. This happens because swsusp arch suspend exit() lacks a CFI hash, but swsusp arch resume() attempts to verify it. The issue arises when calling a copy of swsusp arch suspend exit() during the resume process. The fix involves disabling the CFI check in swsusp arch resume().
Recommendations Update the Linux Kernel to version 6.6.98-android15-8-g0b1d2aee7fc3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-23128
OESA-2026-1642
OESA-2026-1643
OESA-2026-1644
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20873-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8162-1
USN-8180-1
USN-8180-2
USN-8180-3
USN-8180-4
USN-8180-5
USN-8180-6
USN-8186-1
USN-8187-1
USN-8188-1
USN-8243-1
USN-8275-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2
USN-8297-1
USN-8393-1
USN-8440-1
USN-8499-1
USN-8570-1
USN-8570-2
USN-8594-1
USN-8604-1
USN-8605-1

Affected Products

Android
Linux Kernel
Linuxmint
Ubuntu