PT-2026-8202 · Linux · Linux Kernel
Published
2026-01-01
·
Updated
2026-02-14
·
CVE-2026-23194
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel's rust binder component related to handling FDA (fd array) objects. Specifically, the issue arises when processing empty FDA objects with a length of zero, leading to a potential out-of-bounds write error. The previous implementation incorrectly interpreted a skip length of zero, resulting in an attempt to write beyond the allocated buffer when the FDA was located at the end of the buffer. This condition triggered an EINVAL error in userspace. The root cause was identified by Gemini CLI.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel