CVE-2026-23002 is a NULL pointer dereference vulnerability in the Linux kernel lib/buildid code. In the sleepable-context file-reading path, direct page-cache access through read_cache_folio() can result in a NULL pointer dereference in filemap_read_folio. The upstream fix replaces this access with __kernel_read(), using the standard kernel file-reading interface for the faultable path. The non-sleepable path is unchanged by this fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for a claimed stack buffer overflow in a simulated 5G gNodeB NAS parser, labeled CVE-2026-23002. The repository contains four files: a LICENSE, a README describing the issue and usage, a C source file (gnb_nas_sim.c), and a helper shell script (gnb_nas_sim.sh) to compile and run the demo. The core exploit logic is entirely in gnb_nas_sim.c. The function process_registration_request() allocates a fixed 128-byte stack buffer (ie_buffer), parses a 16-bit Information Element length from the first two bytes of an attacker-controlled message, and copies ie_length bytes from the message into the stack buffer using memcpy without validating that ie_length fits within MAX_IE_SIZE. The main() function constructs a malicious NAS-like message with IE length 256 (0x0100), then attempts to fill 254 bytes of attacker-controlled data and pass the message to the vulnerable parser, demonstrating the overflow condition. Capabilities: the code demonstrates stack memory corruption via oversized length-controlled copy. Its practical result is a local crash/segmentation fault in the simulation. It does not include shellcode, ROP, reverse shell, persistence, or post-exploitation logic. Therefore it is best classified as a POC rather than an operational or weaponized exploit. Attack surface: conceptually, the vulnerability described is a remote network attack against a gNodeB receiving crafted NAS Registration Request data. However, this repository does not implement any radio, SCTP, NGAP, or IP-based delivery path; it only simulates the vulnerable parsing routine locally in C. The shell script simply compiles the binary with weakened protections (-fno-stack-protector and -z execstack) and runs it. Notable caveat: the repository appears to be a synthetic demonstration rather than a real exploit against an identifiable vendor product. No actual network endpoints, IPs, domains, sockets, or protocol handlers are present in the exploit code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel vulnerability involving lib/buildid use of __kernel_read() in a sleepable context, affecting Rocky Linux 9 kernel packages.
CVE listed in the advisory references section for kernel CVEs, but no vulnerability details are provided in the content body.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.