CVE-2026-23327 | Linux Kernel up to 6.19.6/7.0-rc1 mbox cxl_payload_from_user_allowed in_size null pointer dereference
A vulnerability labeled as critical has been found in Linux Kernel up to 6.19.6/7.0-rc1. Affected by this vulnerability is the function cxl_payload_from_user_allowed of the component mbox. The manipulation of the argument in_size results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-23327. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.