CVE-2026-23274

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer. If the label was created first by revision 1 with XT_IDLETIMER_ALARM, the object uses alarm timer semantics and timer->timer is never initialized. Reusing that object from revision 0 causes mod_timer() on an uninitialized timer_list, triggering debugobjects warnings and possible panic when panic_on_warn=1. Fix this by rejecting revision 0 rule insertion when an existing timer with the same label is of ALARM type.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*

History

22 May 2026, 18:17

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/144f88054ba0180467356f40895bd660b5dceeec - () https://git.kernel.org/stable/c/144f88054ba0180467356f40895bd660b5dceeec - Patch
References () https://git.kernel.org/stable/c/28c7cfaf0c0ab17cbd7754092116fd1af45271f9 - () https://git.kernel.org/stable/c/28c7cfaf0c0ab17cbd7754092116fd1af45271f9 - Patch
References () https://git.kernel.org/stable/c/329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf - () https://git.kernel.org/stable/c/329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf - Patch
References () https://git.kernel.org/stable/c/32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44 - () https://git.kernel.org/stable/c/32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44 - Patch
References () https://git.kernel.org/stable/c/54080355999381fed4a26129579a5765bab87491 - () https://git.kernel.org/stable/c/54080355999381fed4a26129579a5765bab87491 - Patch
References () https://git.kernel.org/stable/c/5e7ece24c5cb75a60402aad4d803c7898ea40aa9 - () https://git.kernel.org/stable/c/5e7ece24c5cb75a60402aad4d803c7898ea40aa9 - Patch
References () https://git.kernel.org/stable/c/f228b9ae2a7e84d1153616d8e71c4236cb1f1309 - () https://git.kernel.org/stable/c/f228b9ae2a7e84d1153616d8e71c4236cb1f1309 - Patch
References () https://git.kernel.org/stable/c/f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1 - () https://git.kernel.org/stable/c/f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1 - Patch
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
CWE NVD-CWE-noinfo

18 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/144f88054ba0180467356f40895bd660b5dceeec -
  • () https://git.kernel.org/stable/c/32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44 -

02 Apr 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

25 Mar 2026, 11:16

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: netfilter: xt_IDLETIMER: rechazar la reutilización de rev0 de etiquetas de temporizador ALARM Las reglas de la revisión 0 de IDLETIMER reutilizan temporizadores existentes por etiqueta y siempre llaman a mod_timer() en timer->timer. Si la etiqueta fue creada primero por la revisión 1 con XT_IDLETIMER_ALARM, el objeto utiliza semántica de temporizador de alarma y timer->timer nunca se inicializa. Reutilizar ese objeto de la revisión 0 causa mod_timer() en una timer_list no inicializada, lo que activa advertencias de debugobjects y un posible pánico cuando panic_on_warn=1. Solucione esto rechazando la inserción de reglas de la revisión 0 cuando un temporizador existente con la misma etiqueta es de tipo ALARM.
References
  • () https://git.kernel.org/stable/c/28c7cfaf0c0ab17cbd7754092116fd1af45271f9 -
  • () https://git.kernel.org/stable/c/54080355999381fed4a26129579a5765bab87491 -
  • () https://git.kernel.org/stable/c/5e7ece24c5cb75a60402aad4d803c7898ea40aa9 -

20 Mar 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 09:16

Updated : 2026-05-22 18:17


NVD link : CVE-2026-23274

Mitre link : CVE-2026-23274

CVE.ORG link : CVE-2026-23274


JSON object : View

Products Affected

linux

  • linux_kernel