CVE-2026-23391

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_CT: drop pending enqueued packets on template removal Templates refer to objects that can go away while packets are sitting in nfqueue refer to: - helper, this can be an issue on module removal. - timeout policy, nfnetlink_cttimeout might remove it. The use of templates with zone and event cache filter are safe, since this just copies values. Flush these enqueued packets in case the template rule gets removed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.4:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

History

14 Jul 2026, 13:18

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-019113.html -
  • () https://cert-portal.siemens.com/productcert/html/ssa-082556.html -

24 Apr 2026, 18:38

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.4:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/19a230dec6bb8928e3f96387f9085cf2c79bcef9 - () https://git.kernel.org/stable/c/19a230dec6bb8928e3f96387f9085cf2c79bcef9 - Patch
References () https://git.kernel.org/stable/c/55445134d42b84cb0a272e42c98d233ca65eca83 - () https://git.kernel.org/stable/c/55445134d42b84cb0a272e42c98d233ca65eca83 - Patch
References () https://git.kernel.org/stable/c/63b8097cea1923fe82cd598068d0796da8c015ec - () https://git.kernel.org/stable/c/63b8097cea1923fe82cd598068d0796da8c015ec - Patch
References () https://git.kernel.org/stable/c/777d02efe3d630cca4c1b63962cec17c57711325 - () https://git.kernel.org/stable/c/777d02efe3d630cca4c1b63962cec17c57711325 - Patch
References () https://git.kernel.org/stable/c/cb549925875fa06dd155e49db4ac2c5044c30f9c - () https://git.kernel.org/stable/c/cb549925875fa06dd155e49db4ac2c5044c30f9c - Patch
References () https://git.kernel.org/stable/c/cc57506dd66555899560b9c0f24e813f034e12ec - () https://git.kernel.org/stable/c/cc57506dd66555899560b9c0f24e813f034e12ec - Patch
References () https://git.kernel.org/stable/c/d2d0bae0c9a2a17b6990a2966f5cdce0813d6256 - () https://git.kernel.org/stable/c/d2d0bae0c9a2a17b6990a2966f5cdce0813d6256 - Patch
References () https://git.kernel.org/stable/c/f62a218a946b19bb59abdd5361da85fa4606b96b - () https://git.kernel.org/stable/c/f62a218a946b19bb59abdd5361da85fa4606b96b - Patch
First Time Linux
Linux linux Kernel

18 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/55445134d42b84cb0a272e42c98d233ca65eca83 -
  • () https://git.kernel.org/stable/c/cc57506dd66555899560b9c0f24e813f034e12ec -

02 Apr 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: netfilter: xt_CT: descartar paquetes pendientes encolados al eliminar la plantilla Las plantillas se refieren a objetos que pueden desaparecer mientras los paquetes están en nfqueue, se refieren a: - helper, esto puede ser un problema al eliminar el módulo. - política de tiempo de espera, nfnetlink_cttimeout podría eliminarla. El uso de plantillas con filtro de caché de zona y eventos es seguro, ya que esto solo copia valores. Vaciar estos paquetes encolados en caso de que la regla de plantilla sea eliminada.

25 Mar 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 11:16

Updated : 2026-07-14 13:18


NVD link : CVE-2026-23391

Mitre link : CVE-2026-23391

CVE.ORG link : CVE-2026-23391


JSON object : View

Products Affected

linux

  • linux_kernel