PatchSiren cyber security CVE debrief
CVE-2026-23252 Linux CVE debrief
A local denial-of-service vulnerability in the Linux kernel's XFS filesystem scrubber (xfs_scrub) where debug description macros could trigger memory allocation failures. The xchk_xfile_*_descr macros used kasprintf for formatting debug strings, which could fail when formatted output exceeded allocation guarantees. A syzbot fuzzing campaign by Jiaming Zhang identified reachable failure paths. The fix replaces dynamic string formatting with static strings, eliminating the allocation failure path entirely. Affected kernel branches span 6.10 through 6.19.6 with patches backported to stable releases.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-18
- Original CVE updated
- 2026-06-01
- Advisory published
- 2026-03-18
- Advisory updated
- 2026-06-01
Who should care
Linux system administrators running XFS with scrub capabilities exposed to local users; kernel maintainers backporting stable patches; security teams tracking local DoS surfaces in filesystem subsystems.
Technical summary
The XFS filesystem scrubber in the Linux kernel used xchk_xfile_*_descr macros that called kasprintf to generate debug descriptions. These dynamic strings could exceed nofail allocation guarantees (historically 16 bytes), causing allocation failures. Jiaming Zhang identified triggerable paths via syzbot fuzzing. Because the descriptions are non-unique debugging aids, the resolution replaces kasprintf calls with static strings, removing the failure path entirely. The vulnerability is local, requires low privileges, and results in high availability impact (denial of service) with no confidentiality or integrity impact.
Defensive priority
medium
Recommended defensive actions
- Apply stable kernel patches for affected versions (6.10–6.12.77, 6.13–6.18.15, 6.19–6.19.5) or upgrade to patched releases (6.12.78+, 6.18.16+, 6.19.6+).
- Prioritize patching systems where untrusted users can execute XFS scrub operations or where syzbot-style fuzzing surfaces are exposed.
- Monitor kernel logs for XFS scrubber memory allocation failures as potential exploitation indicators on unpatched systems.
- Restrict local access to XFS scrub utilities where patching is delayed, since attack vector requires local privileges per CVSS.
Evidence notes
CVE published 2026-03-18; modified 2026-06-01. NVD marks status Analyzed. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H yields 5.5 Medium. CPE ranges: 6.10 to before 6.12.78, 6.13 to before 6.18.16, 6.19 to before 6.19.6. Four stable kernel patches provided. Weakness listed as NVD-CWE-noinfo. No KEV entry. No known ransomware campaign use indicated.
Official resources
-
CVE-2026-23252 CVE record
CVE.org
-
CVE-2026-23252 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
2026-03-18T18:16:23.233Z