Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-23153— firewire: core: fix race condition against transaction list

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于处理AR响应事件时存在竞争条件,可能导致处理AT请求完成事件时出错。

AI Predicted 6.5 Difficulty: Moderate EPSS 0.07% · P0

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 6

VendorProduct Version RangeStatus
Linux Linux b5725cfa4120a4d234ab112aad151d731531d093< b038874e31fc3caa0b0d5abd259dd54b918ad4a1 affected
b5725cfa4120a4d234ab112aad151d731531d093< 20e01bba2ae4898ce65cdcacd1bd6bec5111abd9 affected
6.18 affected
< 6.18 unaffected
6.18.9≤ 6.18.* unaffected
6.19≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-23153

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
firewire: core: fix race condition against transaction list
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: firewire: core: fix race condition against transaction list The list of transaction is enumerated without acquiring card lock when processing AR response event. This causes a race condition bug when processing AT request completion event concurrently. This commit fixes the bug by put timer start for split transaction expiration into the scope of lock. The value of jiffies in card structure is referred before acquiring the lock.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于处理AR响应事件时存在竞争条件,可能导致处理AT请求完成事件时出错。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux b5725cfa4120a4d234ab112aad151d731531d093 ~ b038874e31fc3caa0b0d5abd259dd54b918ad4a1 -
Linux Linux 6.18 -

II. Public POCs for CVE-2026-23153

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-23153

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-02-14 · 108 CVEs total

CVE-2025-71202 8.8 HIGH iommu/sva: invalidate stale IOTLB entries for kernel address space
CVE-2026-23193 8.8 HIGH scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count()
CVE-2026-23172 8.4 HIGH net: wwan: t7xx: fix potential skb->frags overflow in RX path
CVE-2026-23209 7.8 HIGH macvlan: fix error recovery in macvlan_common_newlink()
CVE-2025-71221 7.8 HIGH dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
CVE-2026-23178 7.8 HIGH HID: i2c-hid: fix potential buffer overflow in i2c_hid_get_report()
CVE-2026-23184 7.8 HIGH binder: fix UAF in binder_netlink_report()
CVE-2026-23185 7.8 HIGH wifi: iwlwifi: mld: cancel mlo_scan_start_wk
CVE-2026-23171 7.8 HIGH bonding: fix use-after-free due to enslave fail after slave array update
CVE-2026-23169 7.8 HIGH mptcp: fix race in mptcp_pm_nl_flush_addrs_doit()
CVE-2026-23191 7.8 HIGH ALSA: aloop: Fix racy access at PCM trigger
CVE-2026-23192 7.8 HIGH linkwatch: use __dev_put() in callers to prevent UAF
CVE-2026-23198 7.8 HIGH KVM: Don't clobber irqfd routing type when deassigning irqfd
CVE-2026-23136 7.5 HIGH libceph: reset sparse-read state in osd_fault()
CVE-2026-23148 7.5 HIGH nvmet: fix race in nvmet_bio_done() leading to NULL pointer dereference
CVE-2026-23139 7.5 HIGH netfilter: nf_conncount: update last_gc only when GC has been performed
CVE-2025-71204 7.5 HIGH smb/server: fix refcount leak in parse_durable_handle_context()
CVE-2026-23161 7.3 HIGH mm/shmem, swap: fix race of truncate and swap entry split
CVE-2026-23204 7.1 HIGH net/sched: cls_u32: use skb_header_pointer_careful()
CVE-2025-71201 7.1 HIGH netfs: Fix early read unlock of page with EOF in middle

Showing top 20 of 108 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-23153

No comments yet


Leave a comment