VDB
CVE-2026-23250
CVE-2026-23250
PUBLISHED
In the Linux kernel, the following vulnerability has been resolved: xfs: check return value of xchk_scrub_create_subord Fix this function to return NULL instead of a mangled ENOMEM, then fix the callers to actually check for a null pointer and return ENOMEM. Most of the corrections here are for code merged between 6.2 and 6.10.
EPSS 0.02% · 4.5th percentile
Risk Scores
EPSS Score
0.02%
4.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| linux | linux_kernel | 6.10, 6.10, 6.10 |
| Linux | Linux | 1a5f6e08d4e379a23da5be974aee50b26a20c5b0, 1a5f6e08d4e379a23da5be974aee50b26a20c5b0, 1a5f6e08d4e379a23da5be974aee50b26a20c5b0 |
Exploit Intelligence
- https://git.kernel.org/stable/c/d6f3f7d4dd8a179394cef03c00993d57f5f68601 (circl)
- https://git.kernel.org/stable/c/2b658d1249666cc55af9484dcf5f45ca438d4ecc (circl)
- https://git.kernel.org/stable/c/b2df809edd8cb7d1c3e19d9f6aabc2bd55d2bfb6 (circl)
- https://git.kernel.org/stable/c/ca27313fb3f23e4ac18532ede4ec1c7cc5814c4a (circl)
- 4593.2.0.yml (github-poc)
- 4593.2.0.yml (github-poc)
- 4593.2.0.yml (github-poc)
- 4593.2.0.yml (github-poc)
- 4628.1.0.yml (github-poc)
- 4628.1.0.yml (github-poc)
…and 6 more exploits
Timeline
- Mar 18, 2026 CVE Published
- Mar 19, 2026 EPSS Score
- Mar 20, 2026 EPSS Score
- Mar 21, 2026 EPSS Score
- Mar 22, 2026 EPSS Score
- Mar 22, 2026 Coalition ESS Score
- Mar 23, 2026 EPSS Score
- Mar 24, 2026 EPSS Score
- Mar 25, 2026 EPSS Score
- Mar 29, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
References
- https://git.kernel.org/stable/c/d6f3f7d4dd8a179394cef03c00993d57f5f68601 url
- https://git.kernel.org/stable/c/2b658d1249666cc55af9484dcf5f45ca438d4ecc url
- https://git.kernel.org/stable/c/b2df809edd8cb7d1c3e19d9f6aabc2bd55d2bfb6 url
- https://git.kernel.org/stable/c/ca27313fb3f23e4ac18532ede4ec1c7cc5814c4a url
- https://nvd.nist.gov/vuln/detail/CVE-2026-23250 advisory
- https://lists.debian.org/debian-security-announce/2026/msg00154.html advisory
- https://lists.debian.org/debian-security-announce/2026/msg00148.html advisory