PT-2026-8148 · Linux · Linux Kernel

Published

2026-01-01

·

Updated

2026-02-14

·

CVE-2026-23153

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the FireWire core when enumerating the transaction list without acquiring the card lock during the processing of an AR response event. This can occur concurrently with the processing of an AT request completion event. The issue is addressed by placing the timer start for split transaction expiration within the scope of the lock, and referencing the jiffies value in the card structure before acquiring the lock.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2026-23153

Affected Products

Linux Kernel