PatchSiren cyber security CVE debrief
CVE-2026-23256 Linux CVE debrief
CVE-2026-23256 is a Linux kernel bug in the liquidio VF setup path where a cleanup loop can miss the failing index after initialization aborts, leaving allocated memory unreleased. The issue is categorized as CWE-193 (off-by-one) and carries a medium severity rating with local, low-privilege impact focused on availability.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-18
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-03-18
- Advisory updated
- 2026-05-21
Who should care
Linux kernel maintainers, distro security teams, and operators running kernels that include the liquidio driver should review this fix, especially if they deploy affected kernel series identified by NVD.
Technical summary
In setup_nic_devices(), a failure branches to setup_nic_dev_free for cleanup. The existing while(i--) loop skips the current failing index, so one allocation is not freed and a memory leak results. The fix changes cleanup to iterate from the current index down to 0 so the failing entry is included. NVD maps the issue to CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H and lists affected Linux kernel ranges across multiple stable branches, with fixes referenced by several kernel.org stable patch links.
Defensive priority
Medium priority. The vulnerability is local and requires low privileges, but it can still degrade system availability through memory leakage in affected kernel builds. Prioritize patching in environments that use the liquidio driver or track the affected kernel branches.
Recommended defensive actions
- Apply the kernel patches referenced in the NVD record and vendor references.
- Verify whether your deployed Linux kernel version falls within the affected ranges listed by NVD.
- If you do not use the liquidio driver, confirm whether it is built or loadable in your kernel configuration and disable it where appropriate.
- Track downstream distro advisories for backported fixes in supported kernel packages.
- Validate patched kernels in staging before rollout, especially on systems that depend on liquidio hardware.
Evidence notes
Source description states the bug was found through code review and compile tested only. The NVD record classifies it as CWE-193 and provides the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. NVD also lists affected Linux kernel version ranges and multiple kernel.org stable patch references.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23256 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23256
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23256 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23256
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/01fbca1e93ec3f39f76c31a8f9afa32ce00da48a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3bf519e39b51cb08a93c0599870b35a23db1031e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4640fa5ad5e1a0dbd1c2d22323b7d70a8107dcfd
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/52b19b3a22306fe452ec9e8ff96063f4bfb77b99
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6cbba46934aefdfb5d171e0a95aec06c24f7ca30
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/71a56b89203ec7e5670d94a61a9b4ae617eca804
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bd680e56e316be92c01568be98d85d7a6c9bd92c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.