CVE-2026-23292Disclosure(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix recursive locking in __configfs_open_file() In flush_write_buffer, &p->frag_sem is acquired and then the loaded store function is called, which, here, is target_core_item_dbroot_store(). This function called filp_open(), following which these functions were called (in reverse order), according to the call trace: down_read __configfs_open_file do_dentry_open vfs_open do_open path_openat do_filp_open file_open_name filp_open target_core_item_dbroot_store flush_write_buffer configfs_write_iter target_core_item_dbroot_store() tries to validate the new file path by trying to open the file path provided to it; however, in this case, the bug report shows: db_root: not a directory: /sys/kernel/config/target/dbroot indicating that the same configfs file was tried to be opened, on which it is currently working on. Thus, it is trying to acquire frag_sem semaphore of the same file of which it already holds the semaphore obtained in flush_write_buffer(), leading to acquiring the semaphore in a nested manner and a possibility of recursive locking. Fix this by modifying target_core_item_dbroot_store() to use kern_path() instead of filp_open() to avoid opening the file using filesystem-specific function __configfs_open_file(), and further modifying it to make this fix compatible.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-26: 1Mentions · 2026-03-31: 1Technical Details · 2026-03-26: 103-2603-31
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-311
General1
Full discourse2 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23292 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23292 #CVE-2026-23292 #CVE   #CyberSecurity #InfoSec https://t.co/kQrER0DFaW

    Post summary

    The tweet merely announces the existence of CVE‑2026‑23292 without providing any proof of concept, exploitation data, patch information, or technical details.

    0000027
    123 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🧯 Another “tiny” locking bug, another reminder that the OS is just people arguing over semaphores. CVE fixes like this matter because one deadlock can freeze everything. https://windowsforum.com/threads/cve-2026-23292-fixing-recursive-locking-in-linux-configfs-scsi-target.407422/ #LinuxKernelSecurity #Cve202623292 #ConfigfsLocking #ScsiTargetDbroot https://t.co/OZzhx47Mgi

    Post summary

    The tweet highlights a deadlock bug (CVE-2026-23292) in Linux's configfs SCSI target, stressing the importance of addressing such issues, but it offers no exploitation or patch details.

    0000048
    1.0K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.3--
OSlinuxlinux_kernel5.3--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more