CVE-2026-23309Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns NULL, event_hist_trigger_parse() jumps to the out_free error path. While kfree() safely handles a NULL pointer, trigger_data_free() does not. This causes a NULL pointer dereference in trigger_data_free() when evaluating data->cmd_ops->set_filter. Fix the problem by adding a NULL pointer check to trigger_data_free(). The problem was found by an experimental code review agent based on gemini-3.1-pro while reviewing backports into v6.18.y.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-25: 2Technical Details · 2026-03-25: 203-2503-28
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-252
Patch2
2026-03-281
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-23309 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23309 #CVE-2026-23309 #CVE   #CyberSecurity #InfoSec https://t.co/4BseqXFUnM

    Post summary

    A new CVE-2026-23309 entry has been announced with unknown risk and unspecified affected products; no additional technical, exploit, or patch information is provided.

    0000028
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-23309 In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns… https://www.cve.org/CVERecord?id=CVE-2026-23309 ----- Traducción: CVE-2026-23309 En … http://infoflow.cloud`

    Post summary

    The post announces that CVE-2026-23309 has been resolved in the Linux kernel with a NULL‑pointer check, providing technical details but no exploit or PoC information.

    0000026
    61 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23309 In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns… https://www.cve.org/CVERecord?id=CVE-2026-23309

    Post summary

    The post announces that CVE‑2026‑23309 in the Linux kernel has been fixed with a null‑pointer check patch, with no evidence of a PoC, exploit, or active attacks.

    00000145
    56.8K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more