CVE-2026-23275General(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: io_uring: ensure ctx->rings is stable for task work flags manipulation If DEFER_TASKRUN | SETUP_TASKRUN is used and task work is added while the ring is being resized, it's possible for the OR'ing of IORING_SQ_TASKRUN to happen in the small window of swapping into the new rings and the old rings being freed. Prevent this by adding a 2nd ->rings pointer, ->rings_rcu, which is protected by RCU. The task work flags manipulation is inside RCU already, and if the resize ring freeing is done post an RCU synchronize, then there's no need to add locking to the fast path of task work additions. Note: this is only done for DEFER_TASKRUN, as that's the only setup mode that supports ring resizing. If this ever changes, then they too need to use the io_ctx_mark_taskrun() helper.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-26)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-22: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 2Patch / Workaround · 2026-03-22: 1Technical Details · 2026-03-22: 103-2203-2503-26
Signal classification2 categories
General
375.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-221
Patch1
2026-03-251
General1
2026-03-262
General2
Full discourse4 posts
  • 堇姬 Naup@naup96721
    General

    My First CVE and my first contribute linux kernel https://naup.mygo.tw/2026/03/23/My-First-CVE-CVE-2026-23275/

    Post summary

    The brief post title and link identifies a new CVE but does not provide details on exploitation, patches, or technical specifics.

    63512429213.1K
    164 followersView on X
  • NSG650@nsg650
    General

    >New Linux CVE (CVE-2026-23275) >Look inside >It's related to io_uring Lol

    Post summary

    A brief note about a new Linux CVE (CVE-2026-23275) associated with io_uring, with no further details.

    1602351515.9K
    3.5K followersView on X
  • Constantin Milos ♏@Tinolle infosec.exchange@Tinolle1955
    General

    https://naup.mygo.tw/2026/03/23/My-First-CVE-CVE-2026-23275/

    Post summary

    The provided text appears to be a brief mention of CVE‑2026‑23275 without explicit technical details, PoC, exploitation evidence, or patch information.

    010114772
    4.6K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23275 In the Linux kernel, the following vulnerability has been resolved: io_uring: ensure ctx->rings is stable for task work flags manipulation If DEFER_TASKRUN | SETUP_… https://www.cve.org/CVERecord?id=CVE-2026-23275

    Post summary

    The CVE-2026-23275 vulnerability in the Linux kernel's io_uring subsystem has been patched, addressing a stability issue with task work flags manipulation.

    00000133
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more