CVE-2026-23179

Source
https://cve.org/CVERecord?id=CVE-2026-23179
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23179.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23179
Downstream
Related
Published
2026-02-14T16:27:10Z
Modified
2026-08-12T03:30:42Z
Summary
nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready()
Details

In the Linux kernel, the following vulnerability has been resolved:

nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready()

When the socket is closed while in TCP_LISTEN a callback is run to flush all outstanding packets, which in turns calls nvmet_tcp_listen_data_ready() with the sk_callback_lock held. So we need to check if we are in TCP_LISTEN before attempting to get the sk_callback_lock() to avoid a deadlock.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23179.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
675b453e024154dd547921c6e6d5b58747ba7e0e
Fixed
6e0c7503a5803d568d56a9f9bca662cd94a14908
Fixed
1c90f930e7b410dd2d75a2a19a85e19c64e98ad5
Fixed
2fa8961d3a6a1c2395d8d560ffed2c782681bade

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23179.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.70
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23179.json"