{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-23236",
        "tracking": {
            "current_release_date": "2026-04-03T12:32:53.747524Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-23236",
            "initial_release_date": "2026-03-04T15:26:17.505007Z",
            "revision_history": [
                {
                    "date": "2026-03-04T15:26:17.505007Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| References created (8)."
                },
                {
                    "date": "2026-03-04T15:26:24.171142Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-04T15:39:16.959722Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products created (8).| Products connected (8).| References created (8)."
                },
                {
                    "date": "2026-03-04T15:39:29.340223Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T15:52:39.823451Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-04T18:43:34.193254Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| Products connected (2)."
                },
                {
                    "date": "2026-03-04T18:43:36.748255Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T00:27:38.637894Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products connected (13).| Product Identifiers created (5).| References created (3)."
                },
                {
                    "date": "2026-03-05T06:43:24.857156Z",
                    "number": "9",
                    "summary": "Description created for source."
                },
                {
                    "date": "2026-03-05T12:20:58.146635Z",
                    "number": "10",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1)."
                },
                {
                    "date": "2026-03-05T12:21:00.504246Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T13:05:40.740474Z",
                    "number": "12",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (2).| References created (13)."
                },
                {
                    "date": "2026-03-05T13:05:42.249481Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-05T14:21:50.609409Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-05T14:21:56.697701Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-08T10:38:53.962328Z",
                    "number": "16",
                    "summary": "Products created (8).| Products connected (2).| Products removed (8)."
                },
                {
                    "date": "2026-03-10T18:35:52.524829Z",
                    "number": "17",
                    "summary": "Source connected.| CVE status created. (valid)| News created (1)."
                },
                {
                    "date": "2026-03-10T18:35:54.783590Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-13T00:43:44.178764Z",
                    "number": "19",
                    "summary": "Products connected (1).| Product Identifiers created (1).| Products removed (1)."
                },
                {
                    "date": "2026-03-13T08:24:53.763967Z",
                    "number": "20",
                    "summary": "Products connected (1).| References created (2)."
                },
                {
                    "date": "2026-03-13T18:43:46.990673Z",
                    "number": "21",
                    "summary": "Products connected (2).| Product Identifiers created (2).| Products removed (1)."
                },
                {
                    "date": "2026-03-13T18:43:49.425497Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-16T03:41:43.903373Z",
                    "number": "23",
                    "summary": "Source connected.| CVE status created. (valid)"
                },
                {
                    "date": "2026-03-16T10:38:04.318736Z",
                    "number": "24",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-03-17T21:27:15.818588Z",
                    "number": "25",
                    "summary": "CVSS created.| Products created (1).| Product Identifiers created (7).| Products connected (6)."
                },
                {
                    "date": "2026-03-17T21:27:17.468886Z",
                    "number": "26",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T12:19:59.115257Z",
                    "number": "27",
                    "summary": "CVSS updated."
                },
                {
                    "date": "2026-03-19T12:20:04.587731Z",
                    "number": "28",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:55:45.472470Z",
                    "number": "29",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:55:48.310182Z",
                    "number": "30",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T18:21:51.045326Z",
                    "number": "31",
                    "summary": "Products connected (1)."
                },
                {
                    "date": "2026-03-20T18:21:54.936401Z",
                    "number": "32",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T20:24:22.465556Z",
                    "number": "33",
                    "summary": "Products connected (1).| References created (1)."
                },
                {
                    "date": "2026-03-21T12:19:56.222463Z",
                    "number": "34",
                    "summary": "Product Remediations created (1)."
                },
                {
                    "date": "2026-03-21T12:19:58.501432Z",
                    "number": "35",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T21:47:44.447480Z",
                    "number": "36",
                    "summary": "Products connected (1).| References created (1)."
                },
                {
                    "date": "2026-03-24T21:47:46.433750Z",
                    "number": "37",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-31T11:05:07.478657Z",
                    "number": "38",
                    "summary": "Products connected (1).| References created (2)."
                },
                {
                    "date": "2026-03-31T11:05:10.062824Z",
                    "number": "39",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-31T12:19:53.790869Z",
                    "number": "40",
                    "summary": "Product Remediations created (1)."
                },
                {
                    "date": "2026-04-02T15:25:55.955514Z",
                    "number": "41",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (7).| Product Identifiers created (7).| References created (8)."
                },
                {
                    "date": "2026-04-02T15:26:02.380827Z",
                    "number": "42",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-02T15:41:23.262983Z",
                    "number": "43",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (18).| References created (8)."
                },
                {
                    "date": "2026-04-02T15:41:40.399962Z",
                    "number": "44",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-03T12:29:11.743016Z",
                    "number": "45",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "45"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1330296",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:amazon:linux_2:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Amazon Linux 2"
                    }
                ],
                "category": "vendor",
                "name": "Amazon"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/azl3",
                                "product": {
                                    "name": "vers:unknown/azl3",
                                    "product_id": "CSAFPID-5247946",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:microsoft:azure_linux:azl3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Azure Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5761981",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:azl3_kernel_6.6.126.1-1:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "azl3 kernel 6.6.126.1-1 on Azure Linux 3.0"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5874034",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:cbl2_kernel_5.15.200.1-1:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0"
                            }
                        ],
                        "category": "product_family",
                        "name": "Open Source Software"
                    }
                ],
                "category": "vendor",
                "name": "Microsoft"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1295663",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Debian Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/6.1.164-1",
                                        "product": {
                                            "name": "vers:deb/6.1.164-1",
                                            "product_id": "CSAFPID-5812295",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/linux@6.1.164-1?distro=bookworm"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "linux"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/5.10.251-1",
                                        "product": {
                                            "name": "vers:deb/5.10.251-1",
                                            "product_id": "CSAFPID-5815374",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/linux@5.10.251-1?distro=bullseye"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "linux"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/6.1.164-1~deb11u1",
                                        "product": {
                                            "name": "vers:deb/6.1.164-1~deb11u1",
                                            "product_id": "CSAFPID-5815375",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/linux-6.1@6.1.164-1~deb11u1?distro=bullseye"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "linux-6.1"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<061cfeb560aa3ddc174153dbe5be9d0b55eb7248",
                                "product": {
                                    "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<061cfeb560aa3ddc174153dbe5be9d0b55eb7248",
                                    "product_id": "CSAFPID-5770436"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<0634e8d650993602fc5b389ff7ac525f6542e141",
                                "product": {
                                    "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<0634e8d650993602fc5b389ff7ac525f6542e141",
                                    "product_id": "CSAFPID-5770439"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<120adae7b42faa641179270c067864544a50ab69",
                                "product": {
                                    "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<120adae7b42faa641179270c067864544a50ab69",
                                    "product_id": "CSAFPID-5770443"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<1c008ad0f0d1c1523902b9cdb08e404129677bfc",
                                "product": {
                                    "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<1c008ad0f0d1c1523902b9cdb08e404129677bfc",
                                    "product_id": "CSAFPID-5770441"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<52917e265aa5f848212f60fc50fc504d8ef12866",
                                "product": {
                                    "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<52917e265aa5f848212f60fc50fc504d8ef12866",
                                    "product_id": "CSAFPID-5770440"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<6167af934f956d3ae1e06d61f45cd0d1004bbe1a",
                                "product": {
                                    "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<6167af934f956d3ae1e06d61f45cd0d1004bbe1a",
                                    "product_id": "CSAFPID-5770437"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<a0321e6e58facb39fe191caa0e52ed9aab6a48fe",
                                "product": {
                                    "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<a0321e6e58facb39fe191caa0e52ed9aab6a48fe",
                                    "product_id": "CSAFPID-5770438"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02",
                                "product": {
                                    "name": "vers:git/3c8a63e22a0802fd56380f6ab305b419f18eb6f5|<f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02",
                                    "product_id": "CSAFPID-5770442"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/5.10.251|<=5.10.*",
                                "product": {
                                    "name": "vers:semver/5.10.251|<=5.10.*",
                                    "product_id": "CSAFPID-5635294"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/5.15.201|<=5.15.*",
                                "product": {
                                    "name": "vers:semver/5.15.201|<=5.15.*",
                                    "product_id": "CSAFPID-5635295"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/6.1.164|<=6.1.*",
                                "product": {
                                    "name": "vers:semver/6.1.164|<=6.1.*",
                                    "product_id": "CSAFPID-5635288"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/6.12.74|<=6.12.*",
                                "product": {
                                    "name": "vers:semver/6.12.74|<=6.12.*",
                                    "product_id": "CSAFPID-5635304"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/6.18.13|<=6.18.*",
                                "product": {
                                    "name": "vers:semver/6.18.13|<=6.18.*",
                                    "product_id": "CSAFPID-5758151"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/6.19.3|<=6.19.*",
                                "product": {
                                    "name": "vers:semver/6.19.3|<=6.19.*",
                                    "product_id": "CSAFPID-5758160"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/6.6.127|<=6.6.*",
                                "product": {
                                    "name": "vers:semver/6.6.127|<=6.6.*",
                                    "product_id": "CSAFPID-5635303"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/<3.2",
                                "product": {
                                    "name": "vers:semver/<3.2",
                                    "product_id": "CSAFPID-1287423"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.2",
                                "product": {
                                    "name": "vers:unknown/3.2",
                                    "product_id": "CSAFPID-1287422"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7.0-rc1|<=*",
                                "product": {
                                    "name": "vers:unknown/7.0-rc1|<=*",
                                    "product_id": "CSAFPID-5669083"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Linux"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.2|<5.10.251",
                                "product": {
                                    "name": "vers:unknown/>=3.2|<5.10.251",
                                    "product_id": "CSAFPID-5839373",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=5.11|<5.15.201",
                                "product": {
                                    "name": "vers:unknown/>=5.11|<5.15.201",
                                    "product_id": "CSAFPID-5839366",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=5.16|<6.1.164",
                                "product": {
                                    "name": "vers:unknown/>=5.16|<6.1.164",
                                    "product_id": "CSAFPID-5731908",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=6.13|<6.18.13",
                                "product": {
                                    "name": "vers:unknown/>=6.13|<6.18.13",
                                    "product_id": "CSAFPID-5839369",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=6.19|<6.19.3",
                                "product": {
                                    "name": "vers:unknown/>=6.19|<6.19.3",
                                    "product_id": "CSAFPID-5839370",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=6.2|<6.6.127",
                                "product": {
                                    "name": "vers:unknown/>=6.2|<6.6.127",
                                    "product_id": "CSAFPID-5839367",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=6.7|<6.12.74",
                                "product": {
                                    "name": "vers:unknown/>=6.7|<6.12.74",
                                    "product_id": "CSAFPID-5839368",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "linux_kernel"
                    }
                ],
                "category": "vendor",
                "name": "Linux"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1330297",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:open_source:linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Open Source Linux Kernel"
                    }
                ],
                "category": "vendor",
                "name": "Open Source"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317177",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:oracle:linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Oracle Linux"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317175",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:5::server"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/10",
                                "product": {
                                    "name": "vers:rpm/10",
                                    "product_id": "CSAFPID-2858634",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:10"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1439321",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 6"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439315",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/9",
                                "product": {
                                    "name": "vers:rpm/9",
                                    "product_id": "CSAFPID-1439319",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:9"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 9"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2858635"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kernel"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1453376"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kernel"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 6"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1453377"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kernel"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1453378"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kernel-rt"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1453379"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kernel"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1453380"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kernel-rt"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1453381"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kernel"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1453382"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "kernel-rt"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 9"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-23236",
            "notes": [
                {
                    "category": "description",
                    "text": "No description is available for this CVE.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-23236"
                },
                {
                    "category": "description",
                    "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: properly copy ioctl memory to kernelspace\n\nThe UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from\nuserspace to kernelspace, and instead directly references the memory,\nwhich can cause problems if invalid data is passed from userspace.  Fix\nthis all up by correctly copying the memory before accessing it within\nthe kernel.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-23236"
                },
                {
                    "category": "description",
                    "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: properly copy ioctl memory to kernelspace\n\nThe UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from\nuserspace to kernelspace, and instead directly references the memory,\nwhich can cause problems if invalid data is passed from userspace.  Fix\nthis all up by correctly copying the memory before accessing it within\nthe kernel.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-23236"
                },
                {
                    "category": "description",
                    "text": "In the Linux kernel, the following vulnerability has been resolved:  fbdev: smscufx: properly copy ioctl memory to kernelspace  The UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from userspace to kernelspace, and instead directly references the memory, which can cause problems if invalid data is passed from userspace.  Fix this all up by correctly copying the memory before accessing it within the kernel.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-23236"
                },
                {
                    "category": "description",
                    "text": "fbdev: smscufx: properly copy ioctl memory to kernelspace",
                    "title": "microsoft - https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Mar"
                },
                {
                    "category": "description",
                    "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: properly copy ioctl memory to kernelspace\n\nThe UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from\nuserspace to kernelspace, and instead directly references the memory,\nwhich can cause problems if invalid data is passed from userspace.  Fix\nthis all up by correctly copying the memory before accessing it within\nthe kernel.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-23236"
                },
                {
                    "category": "description",
                    "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: properly copy ioctl memory to kernelspace\n\nThe UFX_IOCTL_REPORT_DAMAGE ioctl does not properly copy data from\nuserspace to kernelspace, and instead directly references the memory,\nwhich can cause problems if invalid data is passed from userspace.  Fix\nthis all up by correctly copying the memory before accessing it within\nthe kernel.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/23xxx/CVE-2026-23236.json"
                },
                {
                    "category": "other",
                    "text": "0.00013",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.6",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is news data available from source Bleepingcomputer, VENDOR FIX as product remediation category",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score, Is related to a product by vendor Linux, Is related to (a version of) product Linux Kernel, Is related to a product by vendor Debian",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "first_fixed": [
                    "CSAFPID-5812295",
                    "CSAFPID-5815374",
                    "CSAFPID-5815375"
                ],
                "known_affected": [
                    "CSAFPID-5761981",
                    "CSAFPID-1330297",
                    "CSAFPID-5247946",
                    "CSAFPID-1287422",
                    "CSAFPID-5770436",
                    "CSAFPID-5770437",
                    "CSAFPID-5770438",
                    "CSAFPID-5770439",
                    "CSAFPID-5770440",
                    "CSAFPID-5770441",
                    "CSAFPID-5770442",
                    "CSAFPID-5770443",
                    "CSAFPID-1295663",
                    "CSAFPID-5731908",
                    "CSAFPID-5839366",
                    "CSAFPID-5839367",
                    "CSAFPID-5839368",
                    "CSAFPID-5839369",
                    "CSAFPID-5839370",
                    "CSAFPID-5839373",
                    "CSAFPID-5874034",
                    "CSAFPID-1330296",
                    "CSAFPID-1317177",
                    "CSAFPID-1317175"
                ],
                "known_not_affected": [
                    "CSAFPID-5635288",
                    "CSAFPID-5635294",
                    "CSAFPID-5635295",
                    "CSAFPID-5635303",
                    "CSAFPID-5635304",
                    "CSAFPID-5669083",
                    "CSAFPID-5758151",
                    "CSAFPID-5758160",
                    "CSAFPID-1439315",
                    "CSAFPID-1439317",
                    "CSAFPID-1439319",
                    "CSAFPID-1439321",
                    "CSAFPID-1453376",
                    "CSAFPID-1453377",
                    "CSAFPID-1453378",
                    "CSAFPID-1453379",
                    "CSAFPID-1453380",
                    "CSAFPID-1453381",
                    "CSAFPID-1453382",
                    "CSAFPID-2858634",
                    "CSAFPID-2858635",
                    "CSAFPID-1287423"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/23xxx/CVE-2026-23236.json"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-23236.json"
                },
                {
                    "category": "external",
                    "summary": "Source - microsoft",
                    "url": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Mar"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0614.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/"
                },
                {
                    "category": "external",
                    "summary": "Source - hkcert",
                    "url": "https://www.hkcert.org/security-bulletin/debian-linux-kernel-multiple-vulnerabilities_20260316"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/23xxx/CVE-2026-23236.json"
                },
                {
                    "category": "external",
                    "summary": "News - bleepingcomputer",
                    "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://git.kernel.org/stable/c/061cfeb560aa3ddc174153dbe5be9d0b55eb7248"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://git.kernel.org/stable/c/0634e8d650993602fc5b389ff7ac525f6542e141"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://git.kernel.org/stable/c/120adae7b42faa641179270c067864544a50ab69"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://git.kernel.org/stable/c/1c008ad0f0d1c1523902b9cdb08e404129677bfc"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://git.kernel.org/stable/c/52917e265aa5f848212f60fc50fc504d8ef12866"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://git.kernel.org/stable/c/6167af934f956d3ae1e06d61f45cd0d1004bbe1a"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://git.kernel.org/stable/c/a0321e6e58facb39fe191caa0e52ed9aab6a48fe"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://git.kernel.org/stable/c/f1e91bd4efeae48b0f42caed7e8ce2e3a0d05b02"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23236"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030440-CVE-2026-23236-b419@gregkh/T"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0614.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0614"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030437-CVE-2025-71238-76bc@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030436-CVE-2026-23231-1a96@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030439-CVE-2026-23232-b24d@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030439-CVE-2026-23233-4413@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030439-CVE-2026-23234-5cef@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030440-CVE-2026-23235-3b8d@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030440-CVE-2026-23236-b419@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030436-CVE-2026-23237-f6fb@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lore.kernel.org/linux-cve-announce/2026030436-CVE-2026-23238-47f3@gregkh/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://msrc.microsoft.com/update-guide/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.debian.org/debian-security-announce/2026/msg00072.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.debian.org/debian-security-announce/2026/msg00071.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.debian.org/debian-lts-announce/2026/03/msg00002.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.debian.org/debian-lts-announce/2026/03/msg00003.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://alas.aws.amazon.com/AL2/ALAS2KERNEL-5.10-2026-114.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-50160.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://linux.oracle.com/errata/ELSA-2026-6053.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:6053"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "CBL-Mariner Releases",
                    "product_ids": [
                        "CSAFPID-5761981",
                        "CSAFPID-5874034"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1287422",
                        "CSAFPID-1295663",
                        "CSAFPID-1317175",
                        "CSAFPID-1317177",
                        "CSAFPID-1330296",
                        "CSAFPID-1330297",
                        "CSAFPID-5247946",
                        "CSAFPID-5731908",
                        "CSAFPID-5761981",
                        "CSAFPID-5770436",
                        "CSAFPID-5770437",
                        "CSAFPID-5770438",
                        "CSAFPID-5770439",
                        "CSAFPID-5770440",
                        "CSAFPID-5770441",
                        "CSAFPID-5770442",
                        "CSAFPID-5770443",
                        "CSAFPID-5839366",
                        "CSAFPID-5839367",
                        "CSAFPID-5839368",
                        "CSAFPID-5839369",
                        "CSAFPID-5839370",
                        "CSAFPID-5839373",
                        "CSAFPID-5874034"
                    ]
                }
            ],
            "title": "CVE-2026-23236"
        }
    ]
}