Skip to main content
EPSS 0.2%top 93%

Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not over-allocate ftrace memory The pg_remaining calculation in… (CVE-2026-23052)

0
Medium
Published: 02/04/2026 (02/04/2026, 17:16:00 UTC)
Source: GCVE Database
Product: linux-hwe-edge

Description

A vulnerability in the Linux kernel's ftrace subsystem involving incorrect memory allocation calculations has been resolved. The issue arises because the calculation of remaining pages underestimates available capacity when PAGE_SIZE is not a multiple of ENTRY_SIZE, leading to over-allocation of ftrace memory and triggering kernel warnings. This flaw could potentially be exploited to compromise the system. The vulnerability affects multiple Linux kernel versions prior to 6.17.0-1021.21~24.04.1 and related builds. Official patches are available from Ubuntu, and users are advised to update and reboot to apply fixes. Due to an ABI change, recompilation of third-party kernel modules may be necessary after updating. The severity is assessed as medium based on the impact described.

Affected software

Affected versions
<6.17.0-1030.30<6.17.0-1031.31

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/22/2026, 21:33:15 UTC

Technical Analysis

The Linux kernel vulnerability CVE-2026-23052 involves the ftrace subsystem's memory allocation logic. Specifically, the pg_remaining calculation in ftrace_process_locs() assumes that ENTRIES_PER_PAGE multiplied by 2^order equals the actual capacity of the allocated page group. However, because ENTRIES_PER_PAGE is computed via integer division (PAGE_SIZE / ENTRY_SIZE), when PAGE_SIZE is not a multiple of ENTRY_SIZE, the actual capacity is larger than assumed. This causes pg_remaining to be underestimated, resulting in excessive memory allocation and kernel warnings. A similar issue in ftrace_allocate_records() can also cause over-allocation. These flaws have been fixed in Linux kernel versions 6.17.0 and later. Ubuntu has released security updates addressing this and other kernel vulnerabilities, requiring system updates and reboots. The update also requires recompilation of third-party kernel modules due to ABI changes.

Potential Impact

The vulnerability can cause the Linux kernel to allocate more memory than intended in the ftrace subsystem, potentially leading to kernel warnings and instability. While the advisory notes that an attacker could possibly use these issues to compromise the system, no known exploits are reported in the wild. The impact is considered medium severity, reflecting the potential for system compromise but no confirmed active exploitation.

Mitigation Recommendations

Official patches are available and have been released by Ubuntu for affected Linux kernel versions. Users should apply the updates promptly and reboot their systems to ensure the fixes take effect. Due to an ABI change in the kernel updates, recompilation and reinstallation of all third-party kernel modules are required. Follow the vendor's update instructions carefully to fully remediate the vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-qvpg-9fvc-x6cv
Osv Schema Version
1.4.0
Aliases
["CVE-2026-23052"]

Threat ID: 6a498a7827e9c7971936efec

Added to database: 07/04/2026, 22:34:32 UTC

Last enriched: 08/22/2026, 21:33:15 UTC

Last updated: 09/10/2026, 19:36:52 UTC

Views: 68

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses