CVE-2026-23191Patch(linux / linux_kernel)

MEDIUMCVSS 7.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix racy access at PCM trigger The PCM trigger callback of aloop driver tries to check the PCM state and stop the stream of the tied substream in the corresponding cable. Since both check and stop operations are performed outside the cable lock, this may result in UAF when a program attempts to trigger frequently while opening/closing the tied stream, as spotted by fuzzers. For addressing the UAF, this patch changes two things: - It covers the most of code in loopback_check_format() with cable->lock spinlock, and add the proper NULL checks. This avoids already some racy accesses. - In addition, now we try to check the state of the capture PCM stream that may be stopped in this function, which was the major pain point leading to UAF.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-26); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-14: 1Mentions · 2026-04-24: 1Mentions · 2026-04-26: 2Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-26: 1Exploit Tool / Code · 2026-04-26: 1Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-24: 102-1404-2404-2604-27
Signal classification3 categories
Patch
240.0%
General
240.0%
Exploit
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-141
Patch1
2026-04-241
General1
2026-04-262
Exploit1General1
2026-04-271
Patch1
Full discourse5 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Stop chasing kernel CVEs like it's 2026. CVE-2026-23191 (ALSA race) and CVE-2026-23268 (AppArmor bypass) are already patched. But the NEXT one? Read more -> https://tinyurl.com/2hm6nwnt #SUSE https://t.co/tqVyQDUyvQ

    Post summary

    The tweet indicates that CVE-2026-23191 and CVE-2026-23268 have already been patched, with no mention of exploits or vulnerabilities details.

    1000049
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Exploit

    Race conditions never go out of style. CVE-2026-23191 is just the latest example. I turned a boring Rocky Linux advisory into an evergreen guide with a working script, mitigation tricks, and a book that teaches binary analysis. Read more-> https://tinyurl.com/ytz7v3wz #Security https://t.co/XyJWQ3pvQW

    Post summary

    The post promotes a guide for CVE‑2026‑23191 that includes a working exploit script and mitigation tips, but it does not provide technical details or evidence of active exploitation.

    1000064
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    The kernel-rt CVEs (CVE-2025-68741, CVE-2026-23191) from April 2026 are just examples. Here’s how to check, patch, and mitigate – plus the book that turns you from a patcher into a vulnerability hunter. - > http://tinyurl.com/56sjcasz #AlmaLinux #Security https://t.co/QFwfXxlvIa

    Post summary

    The tweet references two kernel‑rt CVEs and directs readers to a link claiming to help with checking, patching, and mitigating, but it does not provide any technical details, PoC, or evidence of active exploitation.

    10000671
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    CVE-2026-23191 (kernel race condition) and CVE-2026-23268 (AppArmor bypass) are classic privilege escalation flaws. Read more: -> https://tinyurl.com/43zmt7n8 https://t.co/5nC0AuhVds

    Post summary

    The tweet lists two new CVEs as classic privilege‑escalation flaws and links to additional information but does not provide details on exploits, patches, or active use.

    1000050
    1.5K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23191 In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix racy access at PCM trigger The PCM trigger callback of aloop driver tries to ch… https://www.cve.org/CVERecord?id=CVE-2026-23191

    Post summary

    CVE-2026-23191 has been fixed in the Linux kernel for a race condition in the ALSA aloop driver; no exploit or PoC details are disclosed.

    00010158
    56.4K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--

Explore more