CVE-2023-26605: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid.
Affected products
- Linux Linux Kernel: from 5.15.75, before 5.15.81 (fixed in 5.15.81); from 5.19.17, before 6.0.0 (fixed in 6.0.0); from 6.0.3, before 6.0.11 (fixed in 6.0.11)
Published 2023-02-26. Last modified 2026-06-17.