In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
IDLETIMER revision 0 rules reuse existing timers by label and always call
mod_timer() on timer->timer.
If the label was created first by revision 1 with XT_IDLETIMER_ALARM,
the object uses alarm timer semantics and timer->timer is never initialized.
Reusing that object from revision 0 causes mod_timer() on an uninitialized
timer_list, triggering debugobjects warnings and possible panic when
panic_on_warn=1.
Fix this by rejecting revision 0 rule insertion when an existing timer with
the same label is of ALARM type.
References
Configurations
Configuration 1 (hide)
|
History
22 May 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/144f88054ba0180467356f40895bd660b5dceeec - Patch | |
| References | () https://git.kernel.org/stable/c/28c7cfaf0c0ab17cbd7754092116fd1af45271f9 - Patch | |
| References | () https://git.kernel.org/stable/c/329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf - Patch | |
| References | () https://git.kernel.org/stable/c/32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44 - Patch | |
| References | () https://git.kernel.org/stable/c/54080355999381fed4a26129579a5765bab87491 - Patch | |
| References | () https://git.kernel.org/stable/c/5e7ece24c5cb75a60402aad4d803c7898ea40aa9 - Patch | |
| References | () https://git.kernel.org/stable/c/f228b9ae2a7e84d1153616d8e71c4236cb1f1309 - Patch | |
| References | () https://git.kernel.org/stable/c/f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1 - Patch | |
| First Time |
Linux
Linux linux Kernel |
|
| CPE | cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo |
18 Apr 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
25 Mar 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References |
|
20 Mar 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-20 09:16
Updated : 2026-05-22 18:17
NVD link : CVE-2026-23274
Mitre link : CVE-2026-23274
CVE.ORG link : CVE-2026-23274
JSON object : View
Products Affected
linux
- linux_kernel
CWE
