CVE-2026-23236: fbdev: smscufx: properly copy ioctl memory to kernelspace
Published Mar 4, 2026
·Updated
fbdev: smscufx: properly copy ioctl memory to kernelspace
Affected Software
10 affected componentsFixes available
linux_kernel
Linux Linux kernel>=3.2<5.10.251
Linux Linux kernel>=5.11<5.15.201
Linux Linux kernel>=5.16<6.1.164
Linux Linux kernel>=6.2<6.6.127
Linux Linux kernel>=6.7<6.12.74
Linux Linux kernel>=6.13<6.18.13
Linux Linux kernel>=6.19<6.19.3
Microsoft azl3 kernel 6.6.126.1-1
Microsoft cbl2 kernel 5.15.200.1-1
Event History
Mar 4, 2026
CVE Published
via MITRE·02:36 PM
Data Sourced
via MITRE·02:36 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityAffected Software
Mar 5, 2026
Data Sourced
via Microsoft·09:04 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·09:04 AM
SeverityAffected Software
Updated
via Microsoft·09:04 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-23236?
The severity of CVE-2026-23236 is classified as medium due to potential information leakage that could lead to system instability.
2
How do I fix CVE-2026-23236?
To fix CVE-2026-23236, update your Linux kernel to the latest stable version where the vulnerability has been patched.
3
What systems are affected by CVE-2026-23236?
CVE-2026-23236 affects the Linux kernel versions that utilize the smscufx driver for framebuffer devices.
4
What type of vulnerability is CVE-2026-23236?
CVE-2026-23236 is a memory management vulnerability that involves improper data handling between userspace and kernelspace.
5
Can CVE-2026-23236 be exploited remotely?
Yes, CVE-2026-23236 can potentially be exploited remotely if an attacker has userspace access to the affected system.