{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-23253",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-01-13T15:37:45.990Z",
        "datePublished": "2026-03-18T17:01:44.126Z",
        "dateUpdated": "2026-08-05T12:20:57.385Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:20:57.385Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-core: fix wrong reinitialization of ringbuffer on reopen\n\ndvb_dvr_open() calls dvb_ringbuffer_init() when a new reader opens the\nDVR device.  dvb_ringbuffer_init() calls init_waitqueue_head(), which\nreinitializes the waitqueue list head to empty.\n\nSince dmxdev->dvr_buffer.queue is a shared waitqueue (all opens of the\nsame DVR device share it), this orphans any existing waitqueue entries\nfrom io_uring poll or epoll, leaving them with stale prev/next pointers\nwhile the list head is reset to {self, self}.\n\nThe waitqueue and spinlock in dvr_buffer are already properly\ninitialized once in dvb_dmxdev_init().  The open path only needs to\nreset the buffer data pointer, size, and read/write positions.\n\nReplace the dvb_ringbuffer_init() call in dvb_dvr_open() with direct\nassignment of data/size and a call to dvb_ringbuffer_reset(), which\nproperly resets pread, pwrite, and error with correct memory ordering\nwithout touching the waitqueue or spinlock."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerability is in the DVB DVR device driver, accessible via opening /dev/dvb/adapter*/dvr* character device files. This requires local system access.\nAC:L - The attacker controls both sides of the race — closing a DVR fd from one thread while reopening it from another. The attacker can reliably trigger the waitqueue reinitialization while stale entries exist.\nPR:L - DVB device files are typically accessible to local users (e.g., via \"video\" group membership). On Android phones, set-top boxes, and embedded media devices, the device user has access to DVB hardware. No elevated privileges are required.\nUI:N - No user interaction is needed. The attacker can open, poll, close, and reopen the DVR device entirely on their own.\nS:U - The vulnerability operates within the kernel's security authority. There is no crossing of security boundaries like VM escape or IOMMU bypass.\nC:H - The waitqueue list corruption creates orphaned entries with stale pointers, which is a use-after-free primitive. UAF gives the attacker control over freed memory contents, enabling arbitrary kernel memory reads.\nI:H - The list corruption from the orphaned waitqueue entries provides write primitives through stale prev/next pointer manipulation. This is a classic kernel list corruption that can be leveraged for arbitrary write and code execution via heap spraying.\nA:H - The stale list pointers will cause a kernel crash/oops when the orphaned wait_queue_entry is removed, as it dereferences corrupted prev/next pointers. This was confirmed by syzbot."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/media/dvb-core/dmxdev.c"
                    ],
                    "versions": [
                        {
                            "version": "34731df288a5ffe4b0c396caf8cd24c6a710a222",
                            "lessThan": "527cfa8a3486b3555c5c15e2f62be484a11398dc",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "34731df288a5ffe4b0c396caf8cd24c6a710a222",
                            "lessThan": "fb378cf89be434ed1f10ab79cc4788fba8ae868d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "34731df288a5ffe4b0c396caf8cd24c6a710a222",
                            "lessThan": "f1e520ca2e83ece6731af6167c9e5e16931ecba0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "34731df288a5ffe4b0c396caf8cd24c6a710a222",
                            "lessThan": "af050ab44fa1b1897a940d7d756e512232f5e5df",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "34731df288a5ffe4b0c396caf8cd24c6a710a222",
                            "lessThan": "d71781bad59b1c9d60d7068004581f9bf19c0c9d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "34731df288a5ffe4b0c396caf8cd24c6a710a222",
                            "lessThan": "cfd94642025e6f71c8f754bdec0800ee95e4f3dd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "34731df288a5ffe4b0c396caf8cd24c6a710a222",
                            "lessThan": "32eb8e4adc207ef31bc6e5ae56bab940b0176066",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "34731df288a5ffe4b0c396caf8cd24c6a710a222",
                            "lessThan": "bfbc0b5b32a8f28ce284add619bf226716a59bc0",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/media/dvb-core/dmxdev.c"
                    ],
                    "versions": [
                        {
                            "version": "2.6.17",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "2.6.17",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.253",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.203",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.167",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.130",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.77",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.17",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.19.7",
                            "lessThanOrEqual": "6.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.17",
                                    "versionEndExcluding": "5.10.253"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.17",
                                    "versionEndExcluding": "5.15.203"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.17",
                                    "versionEndExcluding": "6.1.167"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.17",
                                    "versionEndExcluding": "6.6.130"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.17",
                                    "versionEndExcluding": "6.12.77"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.17",
                                    "versionEndExcluding": "6.18.17"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.17",
                                    "versionEndExcluding": "6.19.7"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.17",
                                    "versionEndExcluding": "7.0"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/527cfa8a3486b3555c5c15e2f62be484a11398dc"
                },
                {
                    "url": "https://git.kernel.org/stable/c/fb378cf89be434ed1f10ab79cc4788fba8ae868d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f1e520ca2e83ece6731af6167c9e5e16931ecba0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/af050ab44fa1b1897a940d7d756e512232f5e5df"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d71781bad59b1c9d60d7068004581f9bf19c0c9d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/cfd94642025e6f71c8f754bdec0800ee95e4f3dd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/32eb8e4adc207ef31bc6e5ae56bab940b0176066"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bfbc0b5b32a8f28ce284add619bf226716a59bc0"
                }
            ],
            "title": "media: dvb-core: fix wrong reinitialization of ringbuffer on reopen",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}