{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2026-23198",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2026-23198"
  ],
  "published": "2026-02-14T16:28:50Z",
  "summary": "KVM: Don't clobber irqfd routing type when deassigning irqfd",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Don't clobber irqfd routing type when deassigning irqfd\n\nWhen deassigning a KVM_IRQFD, don't clobber the irqfd's copy of the IRQ's\nrouting entry as doing so breaks kvm_arch_irq_bypass_del_producer() on x86\nand arm64, which explicitly look for KVM_IRQ_ROUTING_MSI.  Instead, to\nhandle a concurrent routing update, verify that the irqfd is still active\nbefore consuming the routing information.  As evidenced by the x86 and\narm64 bugs, and another bug in kvm_arch_update_irqfd_routing() (see below),\nclobbering the entry type without notifying arch code is surprising and\nerror prone.\n\nAs a bonus, checking that the irqfd is active provides a convenient\nlocation for documenting _why_ KVM must not consume the routing entry for\nan irqfd that is in the process of being deassigned: once the irqfd is\ndeleted from the list (which happens *before* the eventfd is detached), it\nwill no longer receive updates via kvm_irq_routing_update(), and so KVM\ncould deliver an event using stale routing information (relative to\nKVM_SET_GSI_ROUTING returning to userspace).\n\nAs an even better bonus, explicitly checking for the irqfd being active\nfixes a similar bug to the one the clobbering is trying to prevent: if an\nirqfd is deactivated, and then its routing is changed,\nkvm_irq_routing_update() won't invoke kvm_arch_update_irqfd_routing()\n(because the irqfd isn't in the list).  And so if the irqfd is in bypass\nmode, IRQs will continue to be posted using the old routing information.\n\nAs for kvm_arch_irq_bypass_del_producer(), clobbering the routing type\nresults in KVM incorrectly keeping the IRQ in bypass mode, which is\nespecially problematic on AMD as KVM tracks IRQs that are being posted to\na vCPU in a list whose lifetime is tied to the irqfd.\n\nWithout the help of KASAN to detect use-after-free, the most common\nsympton on AMD is a NULL pointer deref in amd_iommu_update_ga() due to\nthe memory for irqfd structure being re-allocated and zeroed, resulting\nin irqfd->irq_bypass_data being NULL when read by\navic_update_iommu_vcpu_affinity():\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000018\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  PGD 40cf2b9067 P4D 40cf2b9067 PUD 408362a067 PMD 0\n  Oops: Oops: 0000 [#1] SMP\n  CPU: 6 UID: 0 PID: 40383 Comm: vfio_irq_test\n  Tainted: G     U  W  O        6.19.0-smp--5dddc257e6b2-irqfd #31 NONE\n  Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE\n  Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.78.2-0 09/05/2025\n  RIP: 0010:amd_iommu_update_ga+0x19/0xe0\n  Call Trace:\n   <TASK>\n   avic_update_iommu_vcpu_affinity+0x3d/0x90 [kvm_amd]\n   __avic_vcpu_load+0xf4/0x130 [kvm_amd]\n   kvm_arch_vcpu_load+0x89/0x210 [kvm]\n   vcpu_load+0x30/0x40 [kvm]\n   kvm_arch_vcpu_ioctl_run+0x45/0x620 [kvm]\n   kvm_vcpu_ioctl+0x571/0x6a0 [kvm]\n   __se_sys_ioctl+0x6d/0xb0\n   do_syscall_64+0x6f/0x9d0\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n  RIP: 0033:0x46893b\n    </TASK>\n  ---[ end trace 0000000000000000 ]---\n\nIf AVIC is inhibited when the irfd is deassigned, the bug will manifest as\nlist corruption, e.g. on the next irqfd assignment.\n\n  list_add corruption. next->prev should be prev (ffff8d474d5cd588),\n                       but was 0000000000000000. (next=ffff8d8658f86530).\n  ------------[ cut here ]------------\n  kernel BUG at lib/list_debug.c:31!\n  Oops: invalid opcode: 0000 [#1] SMP\n  CPU: 128 UID: 0 PID: 80818 Comm: vfio_irq_test\n  Tainted: G     U  W  O        6.19.0-smp--f19dc4d680ba-irqfd #28 NONE\n  Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE\n  Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.78.2-0 09/05/2025\n  RIP: 0010:__list_add_valid_or_report+0x97/0xc0\n  Call Trace:\n   <TASK>\n   avic_pi_update_irte+0x28e/0x2b0 [kvm_amd]\n   kvm_pi_update_irte+0xbf/0x190 [kvm]\n   kvm_arch_irq_bypass_add_producer+0x72/0x90 [kvm]\n   irq_bypass_register_consumer+0xcd/0x170 [irqbypa\n---truncated---",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.1.21-1+rpt1",
        "1:6.1.47-1+rpt2",
        "1:6.1.47-1+rpt4",
        "1:6.1.54-1+rpt2",
        "1:6.1.58-1+rpt2",
        "1:6.1.63-1+rpt1",
        "1:6.1.73-1+rpt1",
        "1:6.6.20-1+rpt1",
        "1:6.6.28-1+rpt1",
        "1:6.6.31-1+rpt1",
        "1:6.6.47-1+rpt1",
        "1:6.6.51-1+rpt1",
        "1:6.6.51-1+rpt2",
        "1:6.6.51-1+rpt3",
        "1:6.6.62-1+rpt1",
        "1:6.6.74-1+rpt1",
        "1:6.12.20-1+rpt1~bpo12+1",
        "1:6.12.25-1+rpt1",
        "1:6.12.34-1+rpt1~bookworm",
        "1:6.12.47-1+rpt1~bookworm",
        "1:6.12.62-1+rpt1~bookworm"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v8",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi2-rpi-v8",
            "binary_version": "1:6.1.47-1+rpt2"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-2712",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-v6",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-v7",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-v7l",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi3-rpi-v8",
            "binary_version": "1:6.1.47-1+rpt4"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi4-rpi-2712",
            "binary_version": "1:6.1.54-1+rpt2"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi4-rpi-v8",
            "binary_version": "1:6.1.54-1+rpt2"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi6-rpi-2712",
            "binary_version": "1:6.1.58-1+rpt2"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi6-rpi-v8",
            "binary_version": "1:6.1.58-1+rpt2"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi7-rpi-2712",
            "binary_version": "1:6.1.63-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi7-rpi-v8",
            "binary_version": "1:6.1.63-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi8-rpi-2712",
            "binary_version": "1:6.1.73-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi8-rpi-v8",
            "binary_version": "1:6.1.73-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.20+rpt-rpi-2712",
            "binary_version": "1:6.6.20-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.20+rpt-rpi-v8",
            "binary_version": "1:6.6.20-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.28+rpt-rpi-2712",
            "binary_version": "1:6.6.28-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.28+rpt-rpi-v8",
            "binary_version": "1:6.6.28-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.31+rpt-rpi-2712",
            "binary_version": "1:6.6.31-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.31+rpt-rpi-v8",
            "binary_version": "1:6.6.31-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.47+rpt-rpi-2712",
            "binary_version": "1:6.6.47-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.47+rpt-rpi-v8",
            "binary_version": "1:6.6.47-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.51+rpt-rpi-2712",
            "binary_version": "1:6.6.51-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.51+rpt-rpi-v8",
            "binary_version": "1:6.6.51-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.51+rpt-rpi-2712",
            "binary_version": "1:6.6.51-1+rpt2"
          },
          {
            "binary_name": "linux-image-6.6.51+rpt-rpi-v8",
            "binary_version": "1:6.6.51-1+rpt2"
          },
          {
            "binary_name": "linux-image-6.6.51+rpt-rpi-2712",
            "binary_version": "1:6.6.51-1+rpt3"
          },
          {
            "binary_name": "linux-image-6.6.51+rpt-rpi-v8",
            "binary_version": "1:6.6.51-1+rpt3"
          },
          {
            "binary_name": "linux-image-6.6.62+rpt-rpi-2712",
            "binary_version": "1:6.6.62-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.62+rpt-rpi-v8",
            "binary_version": "1:6.6.62-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-2712",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v8",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-2712",
            "binary_version": "1:6.12.20-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v8",
            "binary_version": "1:6.12.20-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.25+rpt-rpi-2712",
            "binary_version": "1:6.12.25-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.25+rpt-rpi-v8",
            "binary_version": "1:6.12.25-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-2712",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v8",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.34-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.47+rpt-rpi-2712",
            "binary_version": "1:6.12.47-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.47+rpt-rpi-v8",
            "binary_version": "1:6.12.47-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.47+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.47-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.62+rpt-rpi-2712",
            "binary_version": "1:6.12.62-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.62+rpt-rpi-v8",
            "binary_version": "1:6.12.62-1+rpt1~bookworm"
          },
          {
            "binary_name": "linux-image-6.12.62+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.62-1+rpt1~bookworm"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.1.21-1+rpt1": {
            "linux_commit": "0afb5e98488aed7017b9bf321b575d0177feb7ed",
            "upstream_version": "6.1.21",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.163"
          },
          "1:6.1.47-1+rpt2": {
            "linux_commit": "655fc658a15ae7a6f37103754adb39ba52a9a14e",
            "upstream_version": "6.1.47",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.163"
          },
          "1:6.1.47-1+rpt4": {
            "linux_commit": "655fc658a15ae7a6f37103754adb39ba52a9a14e",
            "upstream_version": "6.1.47",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.163",
            "compiled_filter": false
          },
          "1:6.1.54-1+rpt2": {
            "linux_commit": "2906f7abdc03d4a92b6b0e2e0c87ea2a9dffe8f7",
            "upstream_version": "6.1.54",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.163"
          },
          "1:6.1.58-1+rpt2": {
            "linux_commit": "ccf1586ad0663fa91238ac56abf6340d6d740d18",
            "upstream_version": "6.1.58",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.163"
          },
          "1:6.1.63-1+rpt1": {
            "linux_commit": null,
            "upstream_version": "6.1.63",
            "assessment": "upstream version (no usable Linux commit)",
            "upstream_fixed": "6.1.163"
          },
          "1:6.1.73-1+rpt1": {
            "linux_commit": null,
            "upstream_version": "6.1.73",
            "assessment": "upstream version (no usable Linux commit)",
            "upstream_fixed": "6.1.163"
          },
          "1:6.6.20-1+rpt1": {
            "linux_commit": "6f16847710cc0502450788b9f12f0a14d3429668",
            "upstream_version": "6.6.20",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.6.28-1+rpt1": {
            "linux_commit": "0c341f47adc3578cd5f817aa20ee2b7f9ae6b23e",
            "upstream_version": "6.6.28",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.6.31-1+rpt1": {
            "linux_commit": "c1432b4bae5b6582f4d32ba381459f33c34d1424",
            "upstream_version": "6.6.31",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.6.47-1+rpt1": {
            "linux_commit": "cf64a1dfecc2dc418efdd61701c1a4b185ab4761",
            "upstream_version": "6.6.47",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.6.51-1+rpt1": {
            "linux_commit": "0094eba3f2a4338cfa6854b0b5104d02ba0fa01f",
            "upstream_version": "6.6.51",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.6.51-1+rpt2": {
            "linux_commit": "82a50e430ef1d6eb37d78e25aa572c1f6ea56160",
            "upstream_version": "6.6.51",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.6.51-1+rpt3": {
            "linux_commit": "5aeecea9f4a45248bcf564dec924965e066a7bfd",
            "upstream_version": "6.6.51",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.6.62-1+rpt1": {
            "linux_commit": "dd2394360860d15146c96635796a75b05bb32b61",
            "upstream_version": "6.6.62",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.6.74-1+rpt1": {
            "linux_commit": "a18d9ced4965462cb7b3b4252ada440395105308",
            "upstream_version": "6.6.74",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.124"
          },
          "1:6.12.20-1+rpt1~bpo12+1": {
            "linux_commit": "cd231d4775b14f228606c09f219b48308f6ab3aa",
            "upstream_version": "6.12.20",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.25-1+rpt1": {
            "linux_commit": "3dd2c2c507c271d411fab2e82a2b3b7e0b6d3f16",
            "upstream_version": "6.12.25",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.34-1+rpt1~bookworm": {
            "linux_commit": "8f77e03530f65209a377d25023e912b288e039cd",
            "upstream_version": "6.12.34",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.47-1+rpt1~bookworm": {
            "linux_commit": "359f37f0faefb712add32a39f98751aea67d5c1f",
            "upstream_version": "6.12.47",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.62-1+rpt1~bookworm": {
            "linux_commit": "a1073743767f9e7fdc7017ababd2a07ea0c97c1c",
            "upstream_version": "6.12.62",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          }
        }
      }
    },
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:13",
        "name": "linux"
      },
      "versions": [
        "1:6.12.19-1+rpt1~bpo12+1",
        "1:6.12.19-1+rpt1",
        "1:6.12.20-1+rpt1",
        "1:6.12.25-1+rpt1+trixie",
        "1:6.12.34-1+rpt1",
        "1:6.12.47-1+rpt1",
        "1:6.12.62-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-2712",
            "binary_version": "1:6.12.19-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v8",
            "binary_version": "1:6.12.19-1+rpt1~bpo12+1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-2712",
            "binary_version": "1:6.12.19-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.19+rpt-rpi-v8",
            "binary_version": "1:6.12.19-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-2712",
            "binary_version": "1:6.12.20-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.20+rpt-rpi-v8",
            "binary_version": "1:6.12.20-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.25+rpt-rpi-2712",
            "binary_version": "1:6.12.25-1+rpt1+trixie"
          },
          {
            "binary_name": "linux-image-6.12.25+rpt-rpi-v8",
            "binary_version": "1:6.12.25-1+rpt1+trixie"
          },
          {
            "binary_name": "linux-image-6.12.25+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.25-1+rpt1+trixie"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-2712",
            "binary_version": "1:6.12.34-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v8",
            "binary_version": "1:6.12.34-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.34+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.34-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.47+rpt-rpi-2712",
            "binary_version": "1:6.12.47-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.47+rpt-rpi-v8",
            "binary_version": "1:6.12.47-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.47+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.47-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.62+rpt-rpi-2712",
            "binary_version": "1:6.12.62-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.62+rpt-rpi-v8",
            "binary_version": "1:6.12.62-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.12.62+rpt-rpi-v8-rt",
            "binary_version": "1:6.12.62-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.12.19-1+rpt1~bpo12+1": {
            "linux_commit": "121c2c384b9c2f4790ffb31b2cd25c7d75c8fda0",
            "upstream_version": "6.12.19",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.19-1+rpt1": {
            "linux_commit": "121c2c384b9c2f4790ffb31b2cd25c7d75c8fda0",
            "upstream_version": "6.12.19",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.20-1+rpt1": {
            "linux_commit": "cd231d4775b14f228606c09f219b48308f6ab3aa",
            "upstream_version": "6.12.20",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.25-1+rpt1+trixie": {
            "linux_commit": "3dd2c2c507c271d411fab2e82a2b3b7e0b6d3f16",
            "upstream_version": "6.12.25",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.34-1+rpt1": {
            "linux_commit": "8f77e03530f65209a377d25023e912b288e039cd",
            "upstream_version": "6.12.34",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.47-1+rpt1": {
            "linux_commit": "359f37f0faefb712add32a39f98751aea67d5c1f",
            "upstream_version": "6.12.47",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          },
          "1:6.12.62-1+rpt1": {
            "linux_commit": "a1073743767f9e7fdc7017ababd2a07ea0c97c1c",
            "upstream_version": "6.12.62",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.12.70"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23198"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/959a063e7f12524bc1871ad1f519787967bbcd45"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/2284bc168b148a17b5ca3b37b3d95c411f18a08d"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/6d14ba1e144e796b5fc81044f08cfba9024ca195"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/b61f9b2fcf181451d0a319889478cc53c001123e"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/ff48c9312d042bfbe826ca675e98acc6c623211c"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/4385b2f2843549bfb932e0dcf76bf4b065543a3c"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/b4d37cdb77a0015f51fee083598fa227cc07aaf1"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-08-05T13:16:28Z"
  }
}
