[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-23375":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":19,"aliases":20,"duplicate_of":9,"upstream":21,"downstream":22,"duplicates":29,"related":30,"reserved_at":9,"published_at":31,"modified_at":32,"state":33,"summary":34,"references_raw":43,"kevs":62,"epss":63,"epss_history":66,"metrics":279,"affected":285},"CVE-2026-23375","In the Linux kernel, the following vulnerability has been resolved:\n\nmm: thp: deny THP for files on anonymous inodes\n\nfile_thp_enabled() incorrectly allows THP for files on anonymous inodes\n(e.g. guest_memfd and secretmem). These files are created via\nalloc_file_pseudo(), which does not call get_write_access() and leaves\ninode->i_writecount at 0. Combined with S_ISREG(inode->i_mode) being\ntrue, they appear as read-only regular files when\nCONFIG_READ_ONLY_THP_FOR_FS is enabled, making them eligible for THP\ncollapse.\n\nAnonymous inodes can never pass the inode_is_open_for_write() check\nsince their i_writecount is never incremented through the normal VFS\nopen path. The right thing to do is to exclude them from THP eligibility\naltogether, since CONFIG_READ_ONLY_THP_FOR_FS was designed for real\nfilesystem files (e.g. shared libraries), not for pseudo-filesystem\ninodes.\n\nFor guest_memfd, this allows khugepaged and MADV_COLLAPSE to create\nlarge folios in the page cache via the collapse path, but the\nguest_memfd fault handler does not support large folios. This triggers\nWARN_ON_ONCE(folio_test_large(folio)) in kvm_gmem_fault_user_mapping().\n\nFor secretmem, collapse_file() tries to copy page contents through the\ndirect map, but secretmem pages are removed from the direct map. This\ncan result in a kernel crash:\n\n    BUG: unable to handle page fault for address: ffff88810284d000\n    RIP: 0010:memcpy_orig+0x16/0x130\n    Call Trace:\n     collapse_file\n     hpage_collapse_scan_file\n     madvise_collapse\n\nSecretmem is not affected by the crash on upstream as the memory failure\nrecovery handles the failed copy gracefully, but it still triggers\nconfusing false memory failure reports:\n\n    Memory failure: 0x106d96f: recovery action for clean unevictable\n    LRU page: Recovered\n\nCheck IS_ANON_FILE(inode) in file_thp_enabled() to deny THP for all\nanonymous inode files.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-617","Reachable Assertion","The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.","weakness","Draft","Base",[],[],[],[],[23,25,27],{"_key":24},"DEBIAN-CVE-2026-23375",{"_key":26},"RHSA-2026:21557",{"_key":28},"UBUNTU-CVE-2026-23375",[],[],"2026-03-25T10:27:55.754Z","2026-05-11T22:05:39.614Z","Analyzed",{"cisa_kev":35,"cisa_ransomware":35,"cisa_vendor":9,"epss_severity":36,"epss_score":37,"severity":38,"severity_score":39,"severity_version":40,"severity_source":41,"severity_vector":42,"severity_status":33},false,"low",0.00021,"medium",5.5,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",[44,50,54,58],{"url":45,"sources":46,"tags":48},"https://git.kernel.org/stable/c/08de46a75f91a6661bc1ce0a93614f4bc313c581",[47,41],"cve.org",[49],"Patch",{"url":51,"sources":52,"tags":53},"https://git.kernel.org/stable/c/0524ee56af2c9bfbad152a810f1ca95de8ca00d7",[47,41],[49],{"url":55,"sources":56,"tags":57},"https://git.kernel.org/stable/c/f6fa05f0dddd387417d0c28281ddb951582514d6",[47,41],[49],{"url":59,"sources":60,"tags":61},"https://git.kernel.org/stable/c/dd085fe9a8ebfc5d10314c60452db38d2b75e609",[47,41],[49],[],{"date":64,"score":37,"percentile":65},"2026-06-04",0.06217,[67,71,74,77,80,82,85,89,92,95,98,101,104,107,109,112,115,118,121,124,127,130,133,136,139,142,144,147,150,153,156,159,163,167,170,173,176,179,181,184,187,190,193,196,199,202,205,208,211,214,217,220,223,226,228,231,234,236,239,242,245,248,251,254,257,260,263,266,269,272,275,278],{"date":68,"score":69,"percentile":70},"2026-03-25",0.00018,0.04349,{"date":72,"score":69,"percentile":73},"2026-03-26",0.04379,{"date":75,"score":69,"percentile":76},"2026-03-27",0.04382,{"date":78,"score":69,"percentile":79},"2026-03-28",0.04386,{"date":81,"score":69,"percentile":73},"2026-03-29",{"date":83,"score":69,"percentile":84},"2026-03-30",0.04361,{"date":86,"score":87,"percentile":88},"2026-03-31",0.00023,0.06149,{"date":90,"score":87,"percentile":91},"2026-04-01",0.06152,{"date":93,"score":87,"percentile":94},"2026-04-02",0.06188,{"date":96,"score":87,"percentile":97},"2026-04-03",0.062,{"date":99,"score":87,"percentile":100},"2026-04-04",0.06219,{"date":102,"score":87,"percentile":103},"2026-04-05",0.06221,{"date":105,"score":87,"percentile":106},"2026-04-06",0.0619,{"date":108,"score":87,"percentile":97},"2026-04-07",{"date":110,"score":87,"percentile":111},"2026-04-08",0.06243,{"date":113,"score":87,"percentile":114},"2026-04-09",0.06283,{"date":116,"score":87,"percentile":117},"2026-04-10",0.06286,{"date":119,"score":87,"percentile":120},"2026-04-11",0.06274,{"date":122,"score":87,"percentile":123},"2026-04-12",0.0627,{"date":125,"score":87,"percentile":126},"2026-04-13",0.06259,{"date":128,"score":87,"percentile":129},"2026-04-14",0.06204,{"date":131,"score":87,"percentile":132},"2026-04-15",0.06212,{"date":134,"score":87,"percentile":135},"2026-04-16",0.06218,{"date":137,"score":87,"percentile":138},"2026-04-17",0.06229,{"date":140,"score":87,"percentile":141},"2026-04-18",0.0623,{"date":143,"score":87,"percentile":132},"2026-04-19",{"date":145,"score":87,"percentile":146},"2026-04-20",0.06194,{"date":148,"score":87,"percentile":149},"2026-04-21",0.06379,{"date":151,"score":87,"percentile":152},"2026-04-22",0.06383,{"date":154,"score":87,"percentile":155},"2026-04-23",0.06404,{"date":157,"score":87,"percentile":158},"2026-04-24",0.06394,{"date":160,"score":161,"percentile":162},"2026-04-25",0.00013,0.02114,{"date":164,"score":165,"percentile":166},"2026-04-26",0.00015,0.03044,{"date":168,"score":165,"percentile":169},"2026-04-27",0.0304,{"date":171,"score":165,"percentile":172},"2026-04-28",0.03071,{"date":174,"score":165,"percentile":175},"2026-04-29",0.03089,{"date":177,"score":165,"percentile":178},"2026-04-30",0.03092,{"date":180,"score":165,"percentile":175},"2026-05-01",{"date":182,"score":165,"percentile":183},"2026-05-02",0.03075,{"date":185,"score":165,"percentile":186},"2026-05-03",0.0307,{"date":188,"score":165,"percentile":189},"2026-05-04",0.03063,{"date":191,"score":165,"percentile":192},"2026-05-05",0.0305,{"date":194,"score":165,"percentile":195},"2026-05-06",0.03048,{"date":197,"score":165,"percentile":198},"2026-05-07",0.03072,{"date":200,"score":165,"percentile":201},"2026-05-08",0.03084,{"date":203,"score":165,"percentile":204},"2026-05-09",0.03109,{"date":206,"score":165,"percentile":207},"2026-05-10",0.03122,{"date":209,"score":165,"percentile":210},"2026-05-11",0.03118,{"date":212,"score":165,"percentile":213},"2026-05-12",0.03124,{"date":215,"score":165,"percentile":216},"2026-05-13",0.03143,{"date":218,"score":165,"percentile":219},"2026-05-14",0.03157,{"date":221,"score":165,"percentile":222},"2026-05-15",0.03173,{"date":224,"score":165,"percentile":225},"2026-05-16",0.03186,{"date":227,"score":165,"percentile":225},"2026-05-17",{"date":229,"score":165,"percentile":230},"2026-05-18",0.03164,{"date":232,"score":165,"percentile":233},"2026-05-19",0.03158,{"date":235,"score":165,"percentile":219},"2026-05-20",{"date":237,"score":165,"percentile":238},"2026-05-21",0.03146,{"date":240,"score":69,"percentile":241},"2026-05-22",0.05246,{"date":243,"score":69,"percentile":244},"2026-05-23",0.05234,{"date":246,"score":69,"percentile":247},"2026-05-24",0.05236,{"date":249,"score":69,"percentile":250},"2026-05-25",0.05221,{"date":252,"score":69,"percentile":253},"2026-05-26",0.05219,{"date":255,"score":69,"percentile":256},"2026-05-27",0.0525,{"date":258,"score":69,"percentile":259},"2026-05-28",0.05326,{"date":261,"score":69,"percentile":262},"2026-05-29",0.05338,{"date":264,"score":69,"percentile":265},"2026-05-30",0.05328,{"date":267,"score":69,"percentile":268},"2026-05-31",0.0531,{"date":270,"score":37,"percentile":271},"2026-06-01",0.06327,{"date":273,"score":37,"percentile":274},"2026-06-02",0.0625,{"date":276,"score":37,"percentile":277},"2026-06-03",0.06206,{"date":64,"score":37,"percentile":65},[280],{"source":41,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":281,"cvss_v4_0":9},{"baseScore":39,"baseSeverity":282,"vectorString":42,"impactScore":283,"exploitabilityScore":284},"MEDIUM",6,4.6,[286,309],{"ecosystem":9,"name":287,"vendor":288,"product":288,"cpe_part":289,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":290},"Linux","linux","a",[291,298,301,304,307],{"version":292,"is_range":293,"range_type":47,"version_start":294,"version_start_type":295,"version_end":296,"version_end_type":297,"fixed_in":9},">= 7fbb5e188248c50f737720825da1864ce42536d1, \u003C 08de46a75f91a6661bc1ce0a93614f4bc313c581",true,"7fbb5e188248c50f737720825da1864ce42536d1","including","08de46a75f91a6661bc1ce0a93614f4bc313c581","excluding",{"version":299,"is_range":293,"range_type":47,"version_start":294,"version_start_type":295,"version_end":300,"version_end_type":297,"fixed_in":9},">= 7fbb5e188248c50f737720825da1864ce42536d1, \u003C 0524ee56af2c9bfbad152a810f1ca95de8ca00d7","0524ee56af2c9bfbad152a810f1ca95de8ca00d7",{"version":302,"is_range":293,"range_type":47,"version_start":294,"version_start_type":295,"version_end":303,"version_end_type":297,"fixed_in":9},">= 7fbb5e188248c50f737720825da1864ce42536d1, \u003C f6fa05f0dddd387417d0c28281ddb951582514d6","f6fa05f0dddd387417d0c28281ddb951582514d6",{"version":305,"is_range":293,"range_type":47,"version_start":294,"version_start_type":295,"version_end":306,"version_end_type":297,"fixed_in":9},">= 7fbb5e188248c50f737720825da1864ce42536d1, \u003C dd085fe9a8ebfc5d10314c60452db38d2b75e609","dd085fe9a8ebfc5d10314c60452db38d2b75e609",{"version":308,"is_range":35,"range_type":47,"version_start":308,"version_start_type":295,"version_end":308,"version_end_type":295,"fixed_in":9},"6.8",{"ecosystem":9,"name":310,"vendor":288,"product":311,"cpe_part":312,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":313},"linux kernel","linux_kernel","o",[314,319,323,327,328,330,332,334,336,338,340],{"version":315,"is_range":293,"range_type":316,"version_start":317,"version_start_type":295,"version_end":318,"version_end_type":297,"fixed_in":9},"gte6.8.1_lt6.12.78","cpe","6.8.1","6.12.78",{"version":320,"is_range":293,"range_type":316,"version_start":321,"version_start_type":295,"version_end":322,"version_end_type":297,"fixed_in":9},"gte6.13_lt6.18.17","6.13","6.18.17",{"version":324,"is_range":293,"range_type":316,"version_start":325,"version_start_type":295,"version_end":326,"version_end_type":297,"fixed_in":9},"gte6.19_lt6.19.7","6.19","6.19.7",{"version":308,"is_range":35,"range_type":316,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":329,"is_range":35,"range_type":316,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc1",{"version":331,"is_range":35,"range_type":316,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc2",{"version":333,"is_range":35,"range_type":316,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc3",{"version":335,"is_range":35,"range_type":316,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc4",{"version":337,"is_range":35,"range_type":316,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc5",{"version":339,"is_range":35,"range_type":316,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc6",{"version":341,"is_range":35,"range_type":316,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0:rc7"]