CVE-2026-23121

Source
https://cve.org/CVERecord?id=CVE-2026-23121
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23121.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23121
Downstream
Related
Published
2026-02-14T15:09:51.912Z
Modified
2026-05-18T05:59:43.805953950Z
Summary
mISDN: annotate data-race around dev->work
Details

In the Linux kernel, the following vulnerability has been resolved:

mISDN: annotate data-race around dev->work

dev->work can re read locklessly in mISDNread() and mISDNpoll(). Add READONCE()/WRITEONCE() annotations.

BUG: KCSAN: data-race in mISDNioctl / mISDNread

write to 0xffff88812d848280 of 4 bytes by task 10864 on cpu 1: misdnaddtimer drivers/isdn/mISDN/timerdev.c:175 [inline] mISDNioctl+0x2fb/0x550 drivers/isdn/mISDN/timerdev.c:233 vfsioctl fs/ioctl.c:51 [inline] __dosysioctl fs/ioctl.c:597 [inline] __sesysioctl+0xce/0x140 fs/ioctl.c:583 _x64sysioctl+0x43/0x50 fs/ioctl.c:583 x64syscall+0x14b0/0x3000 arch/x86/include/generated/asm/syscalls64.h:17 dosyscallx64 arch/x86/entry/syscall64.c:63 [inline] dosyscall64+0xd8/0x2c0 arch/x86/entry/syscall64.c:94 entrySYSCALL64afterhwframe+0x77/0x7f

read to 0xffff88812d848280 of 4 bytes by task 10857 on cpu 0: mISDNread+0x1f2/0x470 drivers/isdn/mISDN/timerdev.c:112 doloopreadvwritev fs/readwrite.c:847 [inline] vfsreadv+0x3fb/0x690 fs/readwrite.c:1020 doreadv+0xe7/0x210 fs/read_write.c:1080 __dosysreadv fs/read_write.c:1165 [inline] __sesysreadv fs/read_write.c:1162 [inline] __x64sysreadv+0x45/0x50 fs/readwrite.c:1162 x64syscall+0x2831/0x3000 arch/x86/include/generated/asm/syscalls64.h:20 dosyscallx64 arch/x86/entry/syscall64.c:63 [inline] dosyscall64+0xd8/0x2c0 arch/x86/entry/syscall64.c:94 entrySYSCALL64afterhwframe+0x77/0x7f

value changed: 0x00000000 -> 0x00000001

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23121.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1b2b03f8e514e4f68e293846ba511a948b80243c
Fixed
d5d99cb9e0839093cd53aa3b28176fce2f820ca0
Fixed
13f3b3b87068898056db4c79ee67052fbde11d43
Fixed
accc3f8266d2a49881dbcf78c459477f4efa0ff3
Fixed
fc8ba17fd3337bd8b1913c30b95df0fee00d8fb7
Fixed
aa6e33cd74ca4965f2bbcb025e0b672fb0168a69
Fixed
7ac345a93af31358e18e9606eb7b354691bf6757
Fixed
8175dbf174d487afab81e936a862a8d9b8a1ccb6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23121.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.27
Fixed
5.10.249
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.199
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.162
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.122
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.68
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23121.json"