CVE-2026-23179: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready() When the socket is closed while in TCP_LISTEN a callback is run to flush all outstanding packets, which in turns calls nvmet_tcp_listen_data_ready() with the sk_callback_lock held. So we need to check if we are in TCP_LISTEN before attempting to get the sk_callback_lock() to avoid a deadlock.

Affected products

  • Linux Linux: from 6.7, before 6.12.70 (fixed in 6.12.70); from 6.13, before 6.18.10 (fixed in 6.18.10)

Published 2026-02-14. Last modified 2026-06-17.