In the Linux kernel, the following vulnerability has been resolved:
mm/mseal: update VMA end correctly on merge
Previously we stored the end of the current VMA in curr_end, and then upon iterating to the next VMA updated curr_start to curr_end to advance to the next VMA.
However, this doesn't take into account the fact that a VMA might be updated due to a merge by vma_modify_flags(), which can result in curr_end being stale and thus, upon setting curr_start to curr_end, ending up with an incorrect curr_start on the next iteration.
Resolve the issue by setting curr_end to vma->vm_end unconditionally to ensure this value remains updated should this occur.
While we're here, eliminate this entire class of bug by simply setting const curr_[start/end] to be clamped to the input range and VMAs, which also happens to simplify the logic.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone local Linux kernel proof-of-concept for CVE-2026-23416, not part of a larger exploit framework. It contains one C source file implementing the trigger and two Markdown files providing vulnerability background, reproduction notes, and references. The exploit capability is limited to deterministic triggering of a kernel mm/mseal logic flaw affecting VMA iteration/merge handling. The PoC uses raw syscalls for memfd_create, mmap, and mseal to construct overlapping fixed-address VMAs backed by memfd objects, partially seals one mapping, then issues a second mseal across mixed sealed/unsealed VMAs. This causes stale curr_end/curr_start state during mseal_apply() iteration after VMA merging. On CONFIG_DEBUG_VM kernels, the result is a reproducible kernel WARNING at mm/vma.c:830 via vma_merge_existing_range(); on non-debug kernels, the repository claims the bug silently undermines the intended VM_SEALED protection semantics. The code does not attempt privilege escalation, persistence, remote access, or arbitrary code execution. Repository structure: - README.md: detailed vulnerability description, affected/fixed versions, call path, build/run instructions, expected output, and references. - cve-2026-23416-poc.c: main PoC implementation. setup_workspace() creates fixed mmap regions; trigger() creates two memfd-backed mappings at hardcoded addresses, performs two mseal syscalls, and induces the warning condition; main() loops by forking child processes to repeatedly trigger and then checks dmesg for the warning count. - desc.md: supplemental publication/update notes, fix commit hashes, and sample dmesg output confirming the call path. Notable observables are local rather than network-based: hardcoded mmap addresses (0x21da6000, 0x21da8000, 0x200000000000-range), syscall numbers (__NR_memfd_create 319 and __NR_mseal 462), and use of the local dmesg command with grep for 'WARNING.*vma\.c:830'. There are no C2 endpoints, remote URLs contacted by the executable, or external payload downloads. Overall, this is a credible local kernel bug reproducer intended for research and validation of the CVE rather than a weaponized exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.