PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23306 Linux CVE debrief

A use-after-free vulnerability was found in the Linux kernel's pm8001 module. When the pm8001_queue_command() function handles a phy down or device gone state, it updates the task status and calls task_done, which frees the underlying SAS task. However, the function returns -ENODEV to the caller, which can lead to a double free scenario when libsas sas_ata_qc_issue() receives this error value and attempts to clean up and free the task again.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-25
Original CVE updated
2026-05-28
Advisory published
2026-03-25
Advisory updated
2026-05-28

Who should care

Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems who need to ensure their systems are up-to-date with the latest security patches.

Why it matters

A use-after-free vulnerability in the Linux kernel's pm8001 module can lead to a double free scenario, potentially causing system crashes or instability. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems need to ensure their systems are up-to-date with the latest security patches.

  • Verify Linux kernel versions and apply patches to prevent use-after-free vulnerability.
  • Monitor Linux kernel updates and apply patches in a timely manner to prevent exploitation.
  • Review system logs for signs of potential exploitation.

Technical summary

The vulnerability is caused by a use-after-free error in the pm8001_queue_command() function. When the function handles a phy down or device gone state, it updates the task status and calls task_done, which frees the underlying SAS task. However, the function returns -ENODEV to the caller, which can lead to a double free scenario. This issue arises in the Linux kernel's pm8001 module, affecting Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems who need to ensure their systems are up-to-date with the latest security patches.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply patches provided by the Linux kernel maintainers to fix the use-after-free vulnerability in the pm8001 module.
  • Update Linux kernel to a version that includes the fix.
  • Monitor Linux kernel updates and apply patches in a timely manner.
  • Verify Linux kernel versions and apply patches to prevent use-after-free vulnerability.
  • Review system logs for signs of potential exploitation.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability was introduced by a commit that refactored pm8001_queue_command(). The issue arises when the function returns -ENODEV in case of phy down or device gone state, leading to a potential double free scenario.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23306 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23306

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23306 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23306

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/227ff4af00abc40b95123cc27ee8079069dcd8d7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/38353c26db28efd984f51d426eac2396d299cca7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/824a7672e3540962d5c77d4c6666254d7aa6f0b3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8b00427317ba7b7ec91252b034009f638d0f311b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c5dc39f8ae055520fd778b7fb0423f11586f15c4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ebbb852ffbc952b95ddb7e3872b67b3e74c6da47

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.