PatchSiren cyber security CVE debrief
CVE-2026-23306 Linux CVE debrief
A use-after-free vulnerability was found in the Linux kernel's pm8001 module. When the pm8001_queue_command() function handles a phy down or device gone state, it updates the task status and calls task_done, which frees the underlying SAS task. However, the function returns -ENODEV to the caller, which can lead to a double free scenario when libsas sas_ata_qc_issue() receives this error value and attempts to clean up and free the task again.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-25
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-03-25
- Advisory updated
- 2026-05-28
Who should care
Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems who need to ensure their systems are up-to-date with the latest security patches.
Why it matters
A use-after-free vulnerability in the Linux kernel's pm8001 module can lead to a double free scenario, potentially causing system crashes or instability. Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems need to ensure their systems are up-to-date with the latest security patches.
- Verify Linux kernel versions and apply patches to prevent use-after-free vulnerability.
- Monitor Linux kernel updates and apply patches in a timely manner to prevent exploitation.
- Review system logs for signs of potential exploitation.
Technical summary
The vulnerability is caused by a use-after-free error in the pm8001_queue_command() function. When the function handles a phy down or device gone state, it updates the task status and calls task_done, which frees the underlying SAS task. However, the function returns -ENODEV to the caller, which can lead to a double free scenario. This issue arises in the Linux kernel's pm8001 module, affecting Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems who need to ensure their systems are up-to-date with the latest security patches.
Defensive priority
Medium
Recommended defensive actions
- Review and apply patches provided by the Linux kernel maintainers to fix the use-after-free vulnerability in the pm8001 module.
- Update Linux kernel to a version that includes the fix.
- Monitor Linux kernel updates and apply patches in a timely manner.
- Verify Linux kernel versions and apply patches to prevent use-after-free vulnerability.
- Review system logs for signs of potential exploitation.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability was introduced by a commit that refactored pm8001_queue_command(). The issue arises when the function returns -ENODEV in case of phy down or device gone state, leading to a potential double free scenario.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23306 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23306
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23306 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23306
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/227ff4af00abc40b95123cc27ee8079069dcd8d7
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/38353c26db28efd984f51d426eac2396d299cca7
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/824a7672e3540962d5c77d4c6666254d7aa6f0b3
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8b00427317ba7b7ec91252b034009f638d0f311b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c5dc39f8ae055520fd778b7fb0423f11586f15c4
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ebbb852ffbc952b95ddb7e3872b67b3e74c6da47
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.