PatchSiren cyber security CVE debrief
CVE-2026-23423 Linux CVE debrief
A MEDIUM severity vulnerability was found in the Linux kernel, specifically in the btrfs_uring_read_extent() function. The vulnerability occurs when the 'pages' object is not freed in case of an error, potentially leading to memory leaks. This issue can cause system crashes or other problems if not addressed. Linux kernel users and administrators should be aware of this vulnerability and take necessary actions to mitigate its effects.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Linux kernel users and administrators should be aware of this vulnerability and take necessary actions to mitigate its effects. This includes reviewing and updating Linux kernel versions to ensure they are not vulnerable and monitoring system logs for potential issues related to this vulnerability.
Technical summary
The vulnerability is caused by the 'pages' object not being freed in the btrfs_uring_read_extent() function in case of an error. This can lead to memory leaks and potentially cause system crashes or other issues. The affected product is the Linux kernel. Linux kernel users and administrators should verify their systems for exposure and apply patches or mitigations as necessary. The issue can cause system crashes or other problems if not addressed. The vulnerability has been resolved through patches provided by the Linux kernel maintainers.
Defensive priority
Medium priority
Recommended defensive actions
- Apply patches provided by the Linux kernel maintainers
- Review and update Linux kernel versions to ensure they are not vulnerable
- Monitor system logs for potential issues related to this vulnerability
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-03T14:16:28.487Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This vulnerability affects the Linux kernel, specifically in the btrfs_uring_read_extent() function, where the 'pages' object is not freed in case of an error, potentially leading to memory leaks. Linux kernel users and administrators should verify their systems for exposure and apply patches or mitigations as necessary.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23423 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23423
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23423 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23423
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3f501412f2079ca14bf68a18d80a2b7a823f1f64
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/628895890b0c9ac9129129e89455da7db95ba343
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d4f210de01eaccac61eee657f676045ef9771d07
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.