PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23296 Linux CVE debrief

A reference-count leak in the Linux kernel SCSI core subsystem can cause host teardown to hang indefinitely. The flaw resides in tagset_refcnt handling: when a SCSI host is destroyed, the leaked reference prevents completion of scsi_remove_host(), leaving processes such as iscsid unresponsive in __wait_for_common(). Local users with privileges to remove SCSI hosts or iSCSI sessions can trigger the hang, resulting in denial of service. The vulnerability affects multiple stable kernel branches from 5.10.223 through 7.0-rc2. Upstream stable kernels have released patches that correct the refcount imbalance.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-25
Original CVE updated
2026-05-26
Advisory published
2026-03-25
Advisory updated
2026-05-26

Who should care

Linux system administrators running iSCSI initiators or other SCSI-based storage; kernel maintainers and distribution security teams packaging stable kernel updates.

Technical summary

The SCSI core in the Linux kernel fails to properly decrement tagset_refcnt during certain teardown paths. When scsi_remove_host() is invoked, the leaked reference causes the function to wait indefinitely in __wait_for_common(), blocking completion of host removal. The iscsid daemon is particularly affected, as observed in call traces showing schedule_timeout and scsi_remove_host. The flaw is local, requires privileges to initiate SCSI host removal, and results in high availability impact (system hang) with no confidentiality or integrity impact.

Defensive priority

medium

Recommended defensive actions

  • Apply the relevant stable kernel patch from the Linux kernel stable tree to correct the tagset_refcnt reference-count imbalance.
  • Reboot into the patched kernel to ensure the fix is active.
  • Monitor system logs for scsi_remove_host or iscsid hang traces after SCSI host or iSCSI session teardown operations.
  • If immediate patching is not feasible, avoid repeated SCSI host removal operations that could trigger the hang condition.

Evidence notes

The CVE description and NVD record identify the bug as a refcount leak for tagset_refcnt in the SCSI core. Affected version ranges are drawn from NVD CPE criteria: 5.10.223+ before 5.11, 5.15.164+ before 5.15.203, 5.19.12+ before 6.0, 6.0.1+ before 6.1.167, 6.2+ before 6.6.130, 6.7+ before 6.12.77, 6.13+ before 6.18.17, 6.19+ before 6.19.7, plus specific 6.0 pre-release and 7.0-rc versions. Kernel.org stable commits are listed as patches. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H yields score 5.5 (MEDIUM).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23296 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23296

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23296 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23296

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0e274674714427dc578bb99db5b86e312d2b57f8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1ac22c8eae81366101597d48360718dff9b9d980

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7c01b680beaf4d3143866b062b8e770e8b237fb8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/944a333c8e4d42256556c1d2ebb6d773a33e0dcd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9f5e4abed9248448aa1b45b12ab0bea4d329b56a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a03d96598d39fdf605d90731db3ef3b13fb8bdc8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ec5c17c687b189dbc09dfdec11b669caa40bc395

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.