Status: UPDATED | Advisory ID: CVE-2026-23424
| CVE | CVE-2026-23424 |
| CVSS Score / Version | 7.1 (High) / CVSS v3.1 |
| Updated | 2026-09-24 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high. |
| Affected products | Linux Linux Kernel |
| Exploitation prediction (EPSS) | 0.12% probability of exploitation in the next 30 days (2% percentile) -- FIRST.org's EPSS model. |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Linux | Linux Kernel |
| Subsystems | General OT |
| Sectors | All Sectors |
In the Linux kernel, the following vulnerability has been resolved:
accel/amdxdna: Validate command buffer payload count
The count field in the command header is used to determine the valid
payload size. Verify that the valid payload does not exceed the remaining
buffer space.
Monitor Linux's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-23424 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-23424 |