CVE-2026-23306Patch(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free in pm8001_queue_command() Commit e29c47fe8946 ("scsi: pm8001: Simplify pm8001_task_exec()") refactors pm8001_queue_command(), however it introduces a potential cause of a double free scenario when it changes the function to return -ENODEV in case of phy down/device gone state. In this path, pm8001_queue_command() updates task status and calls task_done to indicate to upper layer that the task has been handled. However, this also frees the underlying SAS task. A -ENODEV is then returned to the caller. When libsas sas_ata_qc_issue() receives this error value, it assumes the task wasn't handled/queued by LLDD and proceeds to clean up and free the task again, resulting in a double free. Since pm8001_queue_command() handles the SAS task in this case, it should return 0 to the caller indicating that the task has been handled.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-25: 2Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 103-2503-2603-31
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-252
Patch2
2026-03-261
Disclosure1
2026-03-311
General1
Full discourse4 posts
  • CVE@CVEnew
    Patch

    CVE-2026-23306 In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free in pm8001_queue_command() Commit e29c47fe8946 ("scsi: pm8001: S… https://www.cve.org/CVERecord?id=CVE-2026-23306

    Post summary

    CVE-2026-23306 is a use‑after‑free bug in the Linux kernel’s pm8001 SCSI driver that has been fixed by a specific commit, providing a patch for affected systems.

    00010164
    56.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23306 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23306 #CVE-2026-23306 #CVE   #CyberSecurity #InfoSec https://t.co/yeEPzZ4QQR

    Post summary

    A brief CVE alert with no actionable details, technical data, or mitigation information.

    0000027
    123 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🧨 Double-free bugs in pm8001 after -ENODEV? Linux refactors: where “minor control-flow tweak” becomes “boom, memory safety.” This is why QA matters. https://windowsforum.com/threads/linux-cve-2026-23306-pm8001-double-free-from-enodev-after-task_done.407374/ #LinuxKernelSecurity #Pm8001ScsiDriver #Cve202623306 #MemorySafetyBug https://t.co/Hj9fhOSaZl

    Post summary

    The post announces a double‑free vulnerability (CVE‑2026‑23306) in the pm8001 SCSI driver, describing its technical nature but providing no proof‑of‑concept, exploit, or patch details.

    0000025
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-23306 In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free in pm8001_queue_command() Commit e29c47fe8946 ("scsi: pm8001: S… https://www.cve.org/CVERecord?id=CVE-2026-23306 ----- Traducción: CVE-2026-23306 En … http://infoflow.cloud`

    Post summary

    CVE‑2026‑23306 is a use‑after‑free bug in the Linux kernel’s pm8001 SCSI driver that has been patched; no PoC, exploit code, or active exploitation is mentioned.

    0000027
    61 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--

Explore more