PatchSiren cyber security CVE debrief
CVE-2026-23296 Linux CVE debrief
A reference-count leak in the Linux kernel SCSI core subsystem can cause host teardown to hang indefinitely. The flaw resides in tagset_refcnt handling: when a SCSI host is destroyed, the leaked reference prevents completion of scsi_remove_host(), leaving processes such as iscsid unresponsive in __wait_for_common(). Local users with privileges to remove SCSI hosts or iSCSI sessions can trigger the hang, resulting in denial of service. The vulnerability affects multiple stable kernel branches from 5.10.223 through 7.0-rc2. Upstream stable kernels have released patches that correct the refcount imbalance.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-25
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-03-25
- Advisory updated
- 2026-05-26
Who should care
Linux system administrators running iSCSI initiators or other SCSI-based storage; kernel maintainers and distribution security teams packaging stable kernel updates.
Technical summary
The SCSI core in the Linux kernel fails to properly decrement tagset_refcnt during certain teardown paths. When scsi_remove_host() is invoked, the leaked reference causes the function to wait indefinitely in __wait_for_common(), blocking completion of host removal. The iscsid daemon is particularly affected, as observed in call traces showing schedule_timeout and scsi_remove_host. The flaw is local, requires privileges to initiate SCSI host removal, and results in high availability impact (system hang) with no confidentiality or integrity impact.
Defensive priority
medium
Recommended defensive actions
- Apply the relevant stable kernel patch from the Linux kernel stable tree to correct the tagset_refcnt reference-count imbalance.
- Reboot into the patched kernel to ensure the fix is active.
- Monitor system logs for scsi_remove_host or iscsid hang traces after SCSI host or iSCSI session teardown operations.
- If immediate patching is not feasible, avoid repeated SCSI host removal operations that could trigger the hang condition.
Evidence notes
The CVE description and NVD record identify the bug as a refcount leak for tagset_refcnt in the SCSI core. Affected version ranges are drawn from NVD CPE criteria: 5.10.223+ before 5.11, 5.15.164+ before 5.15.203, 5.19.12+ before 6.0, 6.0.1+ before 6.1.167, 6.2+ before 6.6.130, 6.7+ before 6.12.77, 6.13+ before 6.18.17, 6.19+ before 6.19.7, plus specific 6.0 pre-release and 7.0-rc versions. Kernel.org stable commits are listed as patches. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H yields score 5.5 (MEDIUM).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23296 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23296
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23296 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23296
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0e274674714427dc578bb99db5b86e312d2b57f8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1ac22c8eae81366101597d48360718dff9b9d980
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7c01b680beaf4d3143866b062b8e770e8b237fb8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/944a333c8e4d42256556c1d2ebb6d773a33e0dcd
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9f5e4abed9248448aa1b45b12ab0bea4d329b56a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a03d96598d39fdf605d90731db3ef3b13fb8bdc8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ec5c17c687b189dbc09dfdec11b669caa40bc395
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.