CVE-2026-23415Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() During futex_key_to_node_opt() execution, vma->vm_policy is read under speculative mmap lock and RCU. Concurrently, mbind() may call vma_replace_policy() which frees the old mempolicy immediately via kmem_cache_free(). This creates a race where __futex_key_to_node() dereferences a freed mempolicy pointer, causing a use-after-free read of mpol->mode. [ 151.412631] BUG: KASAN: slab-use-after-free in __futex_key_to_node (kernel/futex/core.c:349) [ 151.414046] Read of size 2 at addr ffff888001c49634 by task e/87 [ 151.415969] Call Trace: [ 151.416732] __asan_load2 (mm/kasan/generic.c:271) [ 151.416777] __futex_key_to_node (kernel/futex/core.c:349) [ 151.416822] get_futex_key (kernel/futex/core.c:374 kernel/futex/core.c:386 kernel/futex/core.c:593) Fix by adding rcu to __mpol_put().

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-02); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-02: 3Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Technical Details · 2026-04-02: 2Technical Details · 2026-07-09: 104-0207-0807-09
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-023
Disclosure2General1
2026-07-081
General1
2026-07-091
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-43499,GhostLock: Linux kernel: Stack-UAF and LPE via futex in kernels 2.6.39 till 7.1 https://www.openwall.com/lists/oss-security/2026/07/08/12 Other recent futex bugs CVE-2026-23415, CVE-2026-31554, CVE-2026-52973 https://www.openwall.com/lists/oss-security/2026/07/09/1 All 4 have same CVSS 7.8 per kernel CNA https://x.com/nebusecurity/status/2074663573742338256

    Post summary

    The thread announces CVE-2026-43499 and related futex bugs (CVE-2026-23415, CVE-2026-31554, CVE-2026-52973) as Stack‑UAF and LPE vulnerabilities in Linux kernels up to 7.1, providing technical details and CVSS scores.

    01002774.1K
    4.7K followersView on X
  • Solar Designer@solardiz
    General

    @nebusecurity Can you please bring this to oss-security, preferably with actual detail right in the posting (but do include the blog link as well). Maybe include your thoughts on / comparison to other recent futex bugs CVE-2026-23415, CVE-2026-31554, CVE-2026-52973 with same CVSS. Thank you!

    Post summary

    The message is a request for more detail on several CVEs, with no explicit evidence of exploits, patches, or technical specifics.

    10000326
    13.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-23415) https://vuldb.com/vuln/354861

    Post summary

    The post announces a newly identified Linux Kernel vulnerability, CVE‑2026‑23415, described as having elevated criticality, but provides no further technical or exploitation details.

    0000173
    2.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-23415 In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() During futex_key_to_node… https://www.cve.org/CVERecord?id=CVE-2026-23415

    Post summary

    The note confirms that CVE‑2026‑23415, a use‑after‑free bug in the Linux kernel futex implementation, has been fixed, but it provides no proof of concept, exploit code, active exploitation, or explicit patch details.

    00000156
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-23415 - futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() Intel Report: https://ift.tt/S7atqFH

    Post summary

    The alert announces the discovery of CVE-2026-23415, a Use‑After‑Free flaw in the Linux futex subsystem, and provides an Intel report link for additional details, but does not disclose PoC, exploit, or mitigation steps.

    000002.2K
    281 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.16--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more