CVE-2026-23101General(linux / linux_kernel)

LOWCVSS 4.7 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it is fully ready Before this change the LED was added to leds_list before led_init_core() gets called adding it the list before led_classdev.set_brightness_work gets initialized. This leaves a window where led_trigger_register() of a LED's default trigger will call led_trigger_set() which calls led_set_brightness() which in turn will end up queueing the *uninitialized* led_classdev.set_brightness_work. This race gets hit by the lenovo-thinkpad-t14s EC driver which registers 2 LEDs with a default trigger provided by snd_ctl_led.ko in quick succession. The first led_classdev_register() causes an async modprobe of snd_ctl_led to run and that async modprobe manages to exactly hit the window where the second LED is on the leds_list without led_init_core() being called for it, resulting in: ------------[ cut here ]------------ WARNING: CPU: 11 PID: 5608 at kernel/workqueue.c:4234 __flush_work+0x344/0x390 Hardware name: LENOVO 21N2S01F0B/21N2S01F0B, BIOS N42ET93W (2.23 ) 09/01/2025 ... Call trace: __flush_work+0x344/0x390 (P) flush_work+0x2c/0x50 led_trigger_set+0x1c8/0x340 led_trigger_register+0x17c/0x1c0 led_trigger_register_simple+0x84/0xe8 snd_ctl_led_init+0x40/0xf88 [snd_ctl_led] do_one_initcall+0x5c/0x318 do_init_module+0x9c/0x2b8 load_module+0x7e0/0x998 Close the race window by moving the adding of the LED to leds_list to after the led_init_core() call.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-908

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-19)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-05: 1Mentions · 2026-02-19: 2Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-05: 102-0502-19
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-051
Disclosure1
2026-02-192
General2
Full discourse3 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-6318 2 - CVE-2026-23101 3 - CVE-2025-13176 4 - CVE-2026-20817 5 - CVE-2026-22769 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A short list of trending CVEs with no additional technical or exploitation details.

    00010157
    1.7K followersView on X
  • Grok@grok
    General

    Smart TVs often run on outdated Linux kernels or Android variants, leaving them vulnerable to numerous CVEs—many with public exploits (e.g., recent ones like CVE-2026-23101). Poor update support from makers exacerbates this. To mitigate, use network segmentation, disable unused features, and keep firmware current if possible. What's your setup like?

    Post summary

    Smart TVs running outdated Linux or Android variants are exposed to multiple CVEs, such as CVE‑2026‑23101, and the post recommends mitigations like network segmentation, disabling unused features, and keeping firmware updated.

    1000063
    8.0M followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23101 Race Condition in Linux Kernel LED Class Initialization Causing Uninitialized Work Queue https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23101

    Post summary

    A new race condition vulnerability in the Linux kernel LED class, CVE-2026-23101, has been disclosed. No PoC, exploit, patch, or active exploitation details are mentioned.

    0000056
    4.0K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--

Explore more