CVE-2026-52923 is a Linux kernel vulnerability in ipc_idr_alloc() within the SysV IPC checkpoint/restore path. A requested next identifier is passed to idr_alloc() with a zero upper bound, allowing allocation beyond ipc_mni when the valid identifier tail is occupied. The resulting object identifier uses the narrower SysV IPC index encoding, so subsequent lookup and removal can address an incorrect lower-index slot. For shared-memory objects, shm_destroy() frees the object while its actual high-index IDR entry remains populated with a dangling pointer. A subsequent traversal of the SysV IPC shared-memory listing can dereference freed kernel memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
100 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An ID-allocation range flaw in the Linux kernel IPC subsystem. The fix restricts next_id allocation to the valid ID range. A patched kernel is available through RHSA-2026:77216 and requires a reboot.
A Linux kernel SysV IPC allocation flaw allows the checkpoint/restore path to allocate IDs beyond ipc_mni. ID encoding then truncates the index used for removal, leaving a stale IDR entry referencing freed shared-memory objects and causing a use-after-free. The advisory rates the vulnerability High, with a CVSS v3 base score of 7.8 and a local, low-privilege attack vector. A security update is available in package version 19506.224.80 or later.
A Linux kernel SysV IPC allocation flaw in the checkpoint/restore path permits allocation beyond the valid IPC ID range. Subsequent ID truncation causes removal to address the wrong slot, leaving a dangling shared-memory pointer that can trigger a use-after-free when /proc/sysvipc/shm is traversed. The reference assigns a CVSS v3 score of 7.8, with local access and low privileges required, and high confidentiality, integrity, and availability impacts.
A high-severity Linux kernel vulnerability in the SysV IPC checkpoint/restore allocation path. An unbounded ID allocation can exceed the valid IPC range, causing incorrect object removal and leaving a dangling pointer that is subsequently dereferenced when reading /proc/sysvipc/shm. The reported CVSS v3 score is 7.8, with local access and low privileges required. The fix bounds allocation to ipc_mni; affected Google kernel packages should be updated to version 18867.381.201 or later.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.