PatchSiren cyber security CVE debrief
CVE-2026-23250 Linux CVE debrief
CVE-2026-23250 was published on 2026-03-18 and concerns a Linux kernel XFS bug in the scrub helper path. The advisory says xchk_scrub_create_subord should return NULL rather than a mangled ENOMEM value, and callers must check for NULL and return ENOMEM. NVD rates the issue Medium with high availability impact and no confidentiality or integrity impact, which points to a local denial-of-service risk rather than data compromise.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-18
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-03-18
- Advisory updated
- 2026-05-21
Who should care
Linux kernel maintainers, distro security teams, and administrators of systems that rely on affected Linux kernel builds, especially hosts using XFS and deployments that include the affected scrub code paths.
Technical summary
The supplied description identifies a null-pointer handling flaw in Linux kernel XFS scrub logic: xchk_scrub_create_subord was returning an incorrect ENOMEM-related value instead of NULL, and callers were not reliably checking for a NULL pointer before proceeding. NVD maps the weakness to CWE-476 and scores the issue CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local attack surface with primary availability impact. NVD’s affected CPE criteria list Linux kernel ranges 6.10 through 6.12.75, 6.13 through 6.18.16, and 6.19 through 6.19.6. The advisory text also notes that most corrections relate to code merged between 6.2 and 6.10, which is useful context for backporting and review of vendor kernels.
Defensive priority
Medium. The issue is locally exploitable and primarily affects availability, so it is important for systems that expose XFS-related maintenance paths or run kernels in the affected ranges, but it does not indicate code execution or data exposure in the supplied material.
Recommended defensive actions
- Upgrade Linux kernel packages to versions that include the vendor or upstream fix for CVE-2026-23250.
- Check whether your distribution has backported the XFS scrub fix into supported kernel streams, since affected version ranges may differ from upstream CPE ranges.
- Prioritize hosts that use XFS and run kernels in the NVD-listed vulnerable ranges: 6.10-6.12.75, 6.13-6.18.16, and 6.19-6.19.6.
- Review change management and maintenance windows for kernel rollout, especially on systems where unexpected availability loss is costly.
- After remediation, verify the installed kernel build and vendor advisory status to confirm the fix is actually present.
Evidence notes
This debrief is based only on the supplied CVE metadata, the NVD record metadata, and the official references listed there. The description states the XFS helper should return NULL and callers should check for NULL and return ENOMEM. NVD provides the CVSS vector, CWE-476 mapping, and vulnerable CPE ranges. The kernel.org links are official patch references cited by NVD, but their contents were not independently expanded beyond the metadata supplied here.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23250 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23250
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23250 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23250
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2b658d1249666cc55af9484dcf5f45ca438d4ecc
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b2df809edd8cb7d1c3e19d9f6aabc2bd55d2bfb6
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ca27313fb3f23e4ac18532ede4ec1c7cc5814c4a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d6f3f7d4dd8a179394cef03c00993d57f5f68601
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.