PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23005 Linux CVE debrief

A vulnerability in the Linux kernel's x86/fpu component could allow a local attacker to cause a denial of service. The vulnerability is due to the failure to clear XSTATE_BV[i] in guest XSAVE state when XFD[i]=1. This could cause the kernel to attempt to load state for features that are disabled via the guest's XFD, resulting in a panic. The vulnerability is addressed in kernel versions 5.17.1, 6.1.162, 6.6.122, 6.7, 6.12.67, 6.13, 6.18.7, and later. The vulnerability can be triggered by a local attacker with access to the system, and it has a medium severity level. The vulnerability has been patched, and users are advised to update to the latest kernel version.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Administrators and users of Linux systems, particularly those using kernel versions prior to the patched versions, should be aware of this vulnerability and take steps to mitigate it. This includes updating to the latest kernel version, monitoring system logs for signs of exploitation, and implementing compensating controls.

Technical summary

The Linux kernel's x86/fpu component fails to clear XSTATE_BV[i] in guest XSAVE state when XFD[i]=1. This vulnerability allows a local attacker to cause a denial of service by triggering a kernel panic. The issue arises when the kernel attempts to load state for features disabled via the guest's XFD. The vulnerability is addressed in kernel versions 5.17.1, 6.1.162, 6.6.122, 6.7, 6.12.67, 6.13, 6.18.7, and later. It has a CVSS score of 5.5 and a medium severity level. To mitigate this vulnerability, administrators should update to the latest kernel version, monitor system logs for signs of exploitation, and implement compensating controls. The vulnerability can be triggered by a local attacker with access to the system.

Defensive priority

Medium

Recommended defensive actions

  • Apply patches from Linux kernel maintainers
  • Update to kernel versions 5.17.1, 6.1.162, 6.6.122, 6.7, 6.12.67, 6.13, 6.18.7, or later
  • Monitor system logs for signs of exploitation
  • Implement compensating controls, such as restricting access to sensitive resources
  • Review system configurations and ensure that they are in line with security best practices
  • Perform regular security audits and vulnerability assessments
  • Keep software and systems up-to-date with the latest security patches

Evidence notes

The vulnerability is documented in the Linux kernel's Git repository and has been assigned a CVE identifier. The NVD entry provides additional information on the vulnerability, including its CVSS score and affected products. The vulnerability has been patched, and users are advised to update to the latest kernel version.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23005 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23005

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23005 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23005

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1e2848bda819af569dfe7ab186223855e092a2cb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b45f721775947a84996deb5c661602254ce25ce6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b5995c01ba53d84182ecb9492fc4d91cfe8a362d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/eea6f395ca502c4528314c8112da9b5d65f685eb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f577508cc8a0adb8b4ebe9480bba7683b6149930

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-019113.html

    0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.