CVE-2026-23356Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() Even though we check that we "should" be able to do lc_get_cumulative() while holding the device->al_lock spinlock, it may still fail, if some other code path decided to do lc_try_lock() with bad timing. If that happened, we logged "LOGIC BUG for enr=...", but still did not return an error. The rest of the code now assumed that this request has references for the relevant activity log extents. The implcations are that during an active resync, mutual exclusivity of resync versus application IO is not guaranteed. And a potential crash at this point may not realizs that these extents could have been target of in-flight IO and would need to be resynced just in case. Also, once the request completes, it will give up activity log references it does not even hold, which will trigger a BUG_ON(refcnt == 0) in lc_put(). Fix: Do not crash the kernel for a condition that is harmless during normal operation: also catch "e->refcnt == 0", not only "e == NULL" when being noisy about "al_complete_io() called on inactive extent %u\n". And do not try to be smart and "guess" whether something will work, then be surprised when it does not. Deal with the fact that it may or may not work. If it does not, remember a possible "partially in activity log" state (only possible for requests that cross extent boundaries), and return an error code from drbd_al_begin_io_nonblock(). A latter call for the same request will then resume from where we left off.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 103-2503-2603-27
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-261
Patch1
2026-03-271
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23356 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23356 #CVE-2026-23356 #CVE   #CyberSecurity #InfoSec https://t.co/UeywKgPYql

    Post summary

    The post announces the discovery of CVE-2026-23356 with minimal details, merely providing a link to the NVD entry.

    0000026
    123 followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 Logic bug in drbd, patched because storage I/O state can go sideways. Great reminder: MS/DRBD land = “works on my cluster” is not a security strategy. #WindowsForum https://windowsforum.com/threads/cve-2026-23356-drbd-logic-bug-storage-i-o-availability-risk-and-patch-guidance.407546/ #LinuxKernelSecurity #Drbd #Cve202623356 #ClusterFailover https://t.co/7JWzGTd7Sa

    Post summary

    The post announces that CVE‑2026‑23356, a logic bug in DRBD, has been patched and provides guidance for applying the fix.

    0000025
    1.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23356 In the Linux kernel, the following vulnerability has been resolved: drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() Even though we check that we "should" be ab… https://www.cve.org/CVERecord?id=CVE-2026-23356

    Post summary

    CVE-2026-23356 in the Linux kernel's drbd module has been patched by fixing a logic bug in drbd_al_begin_io_nonblock(); no PoC, exploit, or active exploitation claims are present.

    00000106
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel3.10--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more