CVE-2026-23236
Last modified
CVE-2026-23236 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the memory, which can cause problems if invalid data is passed from userspace. Fix this all up by correctly copying the memory before accessing it within the kernel.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kernelspace The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the memory, which can cause problems if invalid data is passed from userspace. Fix this all up by correctly copying the memory before accessing it within the kernel.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.2, < 5.10.251 |
| Linux | Linux Kernel | >= 5.11, < 5.15.201 |
| Linux | Linux Kernel | >= 5.16, < 6.1.164 |
| Linux | Linux Kernel | >= 6.2, < 6.6.127 |
| Linux | Linux Kernel | >= 6.7, < 6.12.74 |
| Linux | Linux Kernel | >= 6.13, < 6.18.13 |
| Linux | Linux Kernel | >= 6.19, < 6.19.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-23236?
How severe is CVE-2026-23236?
How do I fix CVE-2026-23236?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23230In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-23231In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23232In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-23233In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23234In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23235In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-23237In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-23238In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-23239In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-2324The LatePoint – Calendar Booking Plugin for Appointments and…6.1
- CVE-2026-23240In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-23241In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2026-23236?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
