PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23244 Linux CVE debrief

CVE-2026-23244 is a Linux kernel issue in nvme_pr_read_keys() where a user-controlled num_keys value is used to size an allocation via struct_size(). With the existing PR_KEYS_MAX upper bound, a large input can still drive an allocation attempt of up to about 4 MB, which in turn can trigger allocator warnings when the requested order exceeds MAX_PAGE_ORDER. The kernel fix switches the allocation to kvzalloc().

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-18
Original CVE updated
2026-05-21
Advisory published
2026-03-18
Advisory updated
2026-05-21

Who should care

Linux kernel and distro maintainers, operators of systems that expose NVMe block-device persistent reservation ioctls, and administrators who allow untrusted local users to interact with affected kernel builds.

Technical summary

The vulnerable path is in drivers/nvme/host/pr.c: nvme_pr_read_keys() receives num_keys from userspace and uses it to compute an allocation size. The source record states that the upper limit is PR_KEYS_MAX (64K), but a malicious or buggy caller can still cause an oversized allocation attempt that may exceed the page allocator’s preferred order. The fix is to replace kzalloc() with kvzalloc(), which is better suited for larger allocations. NVD maps the issue to affected Linux kernel branches and rates it CVSS 3.1 HIGH (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).

Defensive priority

High. Apply the kernel fix promptly on affected Linux kernel branches, especially on hosts where local users can reach NVMe persistent reservation ioctls or where kernel stability is a priority.

Recommended defensive actions

  • Upgrade to a Linux kernel release that includes the fix or the relevant stable backport.
  • Review affected kernel branches listed by NVD and ensure each deployed branch is patched.
  • If immediate upgrading is not possible, reduce exposure to NVMe persistent reservation ioctls for untrusted local users where operationally feasible.
  • Monitor for allocator warnings or unusual NVMe persistent reservation ioctl activity on affected systems.
  • Track vendor stable backports referenced in the official kernel patch links and confirm they are present in your build lineage.

Evidence notes

Source description: nvme_pr_read_keys() consumes userspace-controlled num_keys, computes allocation size with struct_size(), and can attempt up to a 4 MB allocation under the PR_KEYS_MAX (64K) cap. The stated fix is to use kvzalloc() instead of kzalloc(). The supplied kernel warning shows the path through nvme_pr_read_keys() and kzalloc_noprof() into the page allocator. NVD marks the issue analyzed, lists Linux kernel CPE ranges across multiple branches, and assigns CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H. The supplied corpus does not indicate KEV inclusion.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23244 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23244

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23244 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23244

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/15fb6d627484ee39ed73e202ef4720e1fa5c898e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5a501379a010690ae9ae88bef62a1bae1aca32e6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/baef52d80093bd686e70b3cb7e0512a40ae76705

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c3320153769f05fd7fe9d840cb555dd3080ae424

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e42ff5abbd14927553b624c0e06d24df76156fe6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.