{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-23236",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-01-13T15:37:45.988Z",
        "datePublished": "2026-03-04T14:36:40.162Z",
        "dateUpdated": "2026-08-05T12:20:48.788Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:20:48.788Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: properly copy ioctl memory to kernelspace\n\nThe UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from\nuserspace to kernelspace, and instead directly references the memory,\nwhich can cause problems if invalid data is passed from userspace.  Fix\nthis all up by correctly copying the memory before accessing it within\nthe kernel."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerability is triggered via a local ioctl syscall (UFX_IOCTL_REPORT_DAMAGE) on the /dev/fb* framebuffer device file. The USB device must be physically present but the attack itself is a local system call.\nAC:L - The attacker can reliably trigger the vulnerability with a single ioctl call. No race condition, special timing, or non-default configuration is required.\nPR:L - Opening /dev/fb* typically requires membership in the video group, which is a low-privilege requirement on desktop/workstation systems. No capabilities or root privileges are needed beyond device file access.\nUI:N - No user interaction is required. The attacker independently issues the ioctl to trigger the vulnerability.\nS:U - The vulnerability stays within the kernel's security scope — there is no escape from a VM, container, or other security boundary.\nC:L - On non-SMAP systems, the kernel reads 16 bytes (struct dloarea: x, y, w, h) from an attacker-controlled kernel address, providing a limited information disclosure primitive through side-channel observation of the subsequent conditional writes and USB transfer behavior.\nI:H - On non-SMAP systems, the kernel conditionally writes constrained values (0 or display resolution integers) to attacker-controlled kernel addresses, providing a write-what-where primitive. Writing 0 to arbitrary kernel addresses is a known exploitation technique for privilege escalation.\nA:H - On SMAP-enabled systems (most modern x86), the direct userspace pointer dereference causes a kernel oops or panic, reliably crashing the system. Even on non-SMAP systems, passing invalid addresses triggers a kernel fault."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/video/fbdev/smscufx.c"
                    ],
                    "versions": [
                        {
                            "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
                            "lessThan": "061cfeb560aa3ddc174153dbe5be9d0b55eb7248",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
                            "lessThan": "6167af934f956d3ae1e06d61f45cd0d1004bbe1a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
                            "lessThan": "a0321e6e58facb39fe191caa0e52ed9aab6a48fe",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
                            "lessThan": "0634e8d650993602fc5b389ff7ac525f6542e141",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
                            "lessThan": "52917e265aa5f848212f60fc50fc504d8ef12866",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
                            "lessThan": "1c008ad0f0d1c1523902b9cdb08e404129677bfc",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
                            "lessThan": "f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
                            "lessThan": "120adae7b42faa641179270c067864544a50ab69",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/video/fbdev/smscufx.c"
                    ],
                    "versions": [
                        {
                            "version": "3.2",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "3.2",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.251",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.201",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.164",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.127",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.74",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.13",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.19.3",
                            "lessThanOrEqual": "6.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.2",
                                    "versionEndExcluding": "5.10.251"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.2",
                                    "versionEndExcluding": "5.15.201"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.2",
                                    "versionEndExcluding": "6.1.164"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.2",
                                    "versionEndExcluding": "6.6.127"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.2",
                                    "versionEndExcluding": "6.12.74"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.2",
                                    "versionEndExcluding": "6.18.13"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.2",
                                    "versionEndExcluding": "6.19.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.2",
                                    "versionEndExcluding": "7.0"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/061cfeb560aa3ddc174153dbe5be9d0b55eb7248"
                },
                {
                    "url": "https://git.kernel.org/stable/c/6167af934f956d3ae1e06d61f45cd0d1004bbe1a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/a0321e6e58facb39fe191caa0e52ed9aab6a48fe"
                },
                {
                    "url": "https://git.kernel.org/stable/c/0634e8d650993602fc5b389ff7ac525f6542e141"
                },
                {
                    "url": "https://git.kernel.org/stable/c/52917e265aa5f848212f60fc50fc504d8ef12866"
                },
                {
                    "url": "https://git.kernel.org/stable/c/1c008ad0f0d1c1523902b9cdb08e404129677bfc"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02"
                },
                {
                    "url": "https://git.kernel.org/stable/c/120adae7b42faa641179270c067864544a50ab69"
                }
            ],
            "title": "fbdev: smscufx: properly copy ioctl memory to kernelspace",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "x_adpType": "supplier",
                "providerMetadata": {
                    "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
                    "shortName": "siemens-SADP",
                    "dateUpdated": "2026-06-02T13:01:07.977Z"
                },
                "affected": [
                    {
                        "vendor": "Siemens",
                        "product": "RUGGEDCOM RST2428P",
                        "versions": [
                            {
                                "status": "affected",
                                "version": "0",
                                "lessThan": "V4.0",
                                "versionType": "custom"
                            }
                        ],
                        "defaultStatus": "unknown"
                    }
                ],
                "references": [
                    {
                        "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
                    }
                ]
            }
        ]
    }
}