CVE-2026-23221Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix use-after-free in driver_override_show() The driver_override_show() function reads the driver_override string without holding the device_lock. However, driver_override_store() uses driver_set_override(), which modifies and frees the string while holding the device_lock. This can result in a concurrent use-after-free if the string is freed by the store function while being read by the show function. Fix this by holding the device_lock around the read operation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Patch: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-18); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-18: 2Mentions · 2026-02-19: 1Technical Details · 2026-02-18: 202-1802-19
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-182
Disclosure1Patch1
2026-02-191
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23221 Use-After-Free Vulnerability in Linux Kernel's Freescale Management Complex Driver https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23221

    Post summary

    The text announces CVE-2026-23221, identifying it as a use‑after‑free vulnerability in the Linux Kernel Freescale Management Complex Driver, without mentioning any PoC, exploit, patch, or active exploitation.

    0000146
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23221 In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix use-after-free in driver_override_show() The driver_override_show() function re… https://www.cve.org/CVERecord?id=CVE-2026-23221

    Post summary

    The Linux kernel CVE-2026-23221, a use‑after‑free in driver_override_show(), has been fixed, with no evidence of PoC, exploitation, or active attacks reported.

    00001177
    56.4K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Linux Kernel (CVE-2026-23221) https://vuldb.com/?id.346524

    Post summary

    The post announces that the severity for CVE-2026-23221, a Linux Kernel vulnerability, has increased, but no further details are supplied.

    0000062
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more