CVE-2026-23112Disclosure(linux / linux_kernel)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/offset values, leading to _copy_to_iter() GPF/KASAN. Guard sg_idx, remaining entries, and sg->length/offset before building the bvec.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-10); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 5d
01234Mentions · 2026-02-13: 3Mentions · 2026-03-31: 1Mentions · 2026-04-03: 1Mentions · 2026-05-10: 4Mentions · 2026-07-08: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-02-13: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-03: 1Technical Details · 2026-05-10: 3Technical Details · 2026-07-08: 102-1303-3104-0305-1007-08
Signal classification3 categories
Disclosure
550.0%
Patch
330.0%
General
220.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-133
Disclosure1General1Patch1
2026-03-311
Disclosure1
2026-04-031
Disclosure1
2026-05-104
Disclosure2General1Patch1
2026-07-081
Patch1
Full discourse10 posts
  • CVE@CVEnew
    Patch

    CVE-2026-23112 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk… https://www.cve.org/CVERecord?id=CVE-2026-23112

    Post summary

    The Linux kernel CVE‑2026‑23112 has been fixed with added bounds checks in nvmet_tcp_build_pdu_iovec, but no PoC, exploit code, or active exploitation reports are provided.

    00010223
    56.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Linux kernel NVMe/TCP out-of-bounds SG read in nvmet_tcp_build_pdu_iovec (CVE-2026-23112) CVE-2026-23112 is a flaw in the Linux kernel NVMe target TCP transport (nvmet-tcp), specifically in nvmet_tcp_build_pdu_iovec when constructing PDU iovecs from cmd->http://req.sg scatter-gather lists. The root cause is missing bounds checks/improper input validation, allowing PDU length/offset values to exceed sg_cnt and produce invalid sg index/length/offset calculations. An attacker can exploit this over the network by sending crafted NVMe/TCP PDUs to a host exposing the NVMe-oF target service, requiring access to the target port but no local privileges. Successful exploitation can crash the kernel (GPF/KASAN in _copy_to_iter()) and potentially enable memory corruption pathways, resulting in denial of service and possible code execution risk in kernel context. 👉 Affected: Linux kernel nvmet-tcp (NVMe target over TCP) - versions with missing sg bounds validation | Upgrade to a kernel release that includes the nvmet_tcp_build_pdu_iovec validation fix

    Post summary

    The post announces a critical Linux kernel CVE, explains its technical details and impact, and urges users to upgrade to a patched kernel release.

    00000145
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-23112 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    An advisory confirms CVE-2026-23112 as a critical vulnerability (CVSS 9.8) without providing PoC, exploit, or patch details.

    0000039
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-23112-linux-linux-kernel #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided content offers only a link and unrelated hashtags, with no explicit details about the CVE, its exploitation, or mitigation.

    0000026
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE: CVE-2026-23112 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmettcpbuildpduiovec…

    Post summary

    The text announces a critical Linux kernel CVE-2026-23112 that has been fixed with added bounds checks in nvmet-tcp, providing a patch to resolve the issue.

    0000054
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-23112 (CVSS 9.8) — linux linux kernel. CVE: CVE-2026-23112 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry announces a critical advisory for CVE-2026-23112 with a CVSS of 9.8, but does not provide any PoC, exploit, or patch details.

    0000043
    197 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-23112: nvmet-tcp: add bounds checks in ... Buffer overflow in NVMe-TCP lets attackers walk past scatter-gather boundaries, triggering KASAN/GPF via malicious PDU ... https://zerodaysignal.com/vulnerability/CVE-2026-23112 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses a buffer‑overflow vulnerability (CVE-2026-23112) in NVMe‑TCP that can trigger kernel memory violations; no PoC, exploit, or patch is referenced.

    0000065
    197 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenClaw Gateway, Privilege Escalation, #CVE-2026-23112 (Medium) https://dailycve.com/openclaw-gateway-privilege-escalation-cve-2026-23112-medium/

    Post summary

    DailyCVE reports a newly disclosed privilege‑escalation vulnerability (CVE‑2026‑23112) affecting OpenClaw Gateway, providing technical details but no PoC, exploit, or patch information at this time.

    0000022
    175 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23112 Linux Kernel Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23112 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces CVE-2026-23112, a Linux kernel vulnerability, and provides links to additional details and a vulnerability notification.

    0000032
    4.0K followersView on X
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting Linux Kernel (CVE-2026-23112) https://vuldb.com/?id.345900

    Post summary

    A brief notice adds CVE-2026-23112 to a vulnerability database, but provides no additional detail on exploitation, patching, or technical specifics.

    0000051
    2.1K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--

Explore more