Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-45855

5.5 · MEDIUM
Published May 27, 2026 linux EPSS 0.17% (6th pctl)

Overview

CVE-2026-45855 is a medium-severity vulnerability affecting linux linux_kernel. It was published on May 27, 2026 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ata: libata-scsi: avoid Non-NCQ command starvation

When a non-NCQ command is issued while NCQ commands are being executed,

ata_scsi_qc_issue() indicates to the SCSI layer that the command issuing

should be deferred by returning SCSI_MLQUEUE_XXX_BUSY. This command

deferring is correct and as mandated by the ACS specifications since

NCQ and non-NCQ commands cannot be mixed.

However, in the case of a host adapter using multiple submission queues,

when the target device is under a constant load of NCQ commands, there

are no guarantees that requeueing the non-NCQ command will be executed

later and it may be deferred again repeatedly as other submission queues

can constantly issue NCQ commands from different CPUs ahead of the

non-NCQ command. This can lead to very long delays for the execution of

non-NCQ commands, and even complete starvation for these commands in the

worst case scenario.

Since the block layer and the S

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.10, < 6.12.77 Affected

Frequently Asked Questions

What is CVE-2026-45855?

CVE-2026-45855 is a medium-severity vulnerability affecting linux linux_kernel. It was published on May 27, 2026 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2026-45855?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-45855?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-45855?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-45855 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.