CVE-2026-23458

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() stores a conntrack pointer in cb->data for the netlink dump callback ctnetlink_exp_ct_dump_table(), but drops the conntrack reference immediately after netlink_dump_start(). When the dump spans multiple rounds, the second recvmsg() triggers the dump callback which dereferences the now-freed conntrack via nfct_help(ct), leading to a use-after-free on ct->ext. The bug is that the netlink_dump_control has no .start or .done callbacks to manage the conntrack reference across dump rounds. Other dump functions in the same file (e.g. ctnetlink_get_conntrack) properly use .start/.done callbacks for this purpose. Fix this by adding .start and .done callbacks that hold and release the conntrack reference for the duration of the dump, and move the nfct_help() call after the cb->args[0] early-return check in the dump callback to avoid dereferencing ct->ext unnecessarily. BUG: KASAN: slab-use-after-free in ctnetlink_exp_ct_dump_table+0x4f/0x2e0 Read of size 8 at addr ffff88810597ebf0 by task ctnetlink_poc/133 CPU: 1 UID: 0 PID: 133 Comm: ctnetlink_poc Not tainted 7.0.0-rc2+ #3 PREEMPTLAZY Call Trace: <TASK> ctnetlink_exp_ct_dump_table+0x4f/0x2e0 netlink_dump+0x333/0x880 netlink_recvmsg+0x3e2/0x4b0 ? aa_sk_perm+0x184/0x450 sock_recvmsg+0xde/0xf0 Allocated by task 133: kmem_cache_alloc_noprof+0x134/0x440 __nf_conntrack_alloc+0xa8/0x2b0 ctnetlink_create_conntrack+0xa1/0x900 ctnetlink_new_conntrack+0x3cf/0x7d0 nfnetlink_rcv_msg+0x48e/0x510 netlink_rcv_skb+0xc9/0x1f0 nfnetlink_rcv+0xdb/0x220 netlink_unicast+0x3ec/0x590 netlink_sendmsg+0x397/0x690 __sys_sendmsg+0xf4/0x180 Freed by task 0: slab_free_after_rcu_debug+0xad/0x1e0 rcu_core+0x5c3/0x9c0
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: netfilter: ctnetlink: corrige uso después de liberación en ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() almacena un puntero conntrack en cb -> data para la devolución de llamada de volcado netlink ctnetlink_exp_ct_dump_table(), pero libera la referencia conntrack inmediatamente después de netlink_dump_start(). Cuando el volcado abarca múltiples rondas, el segundo recvmsg() activa la devolución de llamada de volcado que desreferencia el conntrack ahora liberado a través de nfct_help(ct), lo que lleva a un uso después de liberación en ct -> ext. El error es que netlink_dump_control no tiene devoluciones de llamada .start o .done para gestionar la referencia conntrack a través de las rondas de volcado. Otras funciones de volcado en el mismo archivo (p. ej., ctnetlink_get_conntrack) utilizan correctamente las devoluciones de llamada .start/.done para este propósito. Solucione esto añadiendo devoluciones de llamada .start y .done que retienen y liberan la referencia conntrack durante la duración del volcado, y mueva la llamada a nfct_help() después de la comprobación de retorno anticipado cb -> args[0] en la devolución de llamada de volcado para evitar desreferenciar ct -> ext innecesariamente. ERROR: KASAN: uso después de liberación de slab en ctnetlink_exp_ct_dump_table+0x4f/0x2e0 Lectura de tamaño 8 en la dirección ffff88810597ebf0 por la tarea ctnetlink_poc/133 CPU: 1 UID: 0 PID: 133 Comm: ctnetlink_poc No contaminado 7.0.0-rc2+ #3 PREEMPTLAZY Traza de Llamada: <TAREA> ctnetlink_exp_ct_dump_table+0x4f/0x2e0 netlink_dump+0x333/0x880 netlink_recvmsg+0x3e2/0x4b0 ? aa_sk_perm+0x184/0x450 sock_recvmsg+0xde/0xf0 Asignado por la tarea 133: kmem_cache_alloc_noprof+0x134/0x440 __nf_conntrack_alloc+0xa8/0x2b0 ctnetlink_create_conntrack+0xa1/0x900 ctnetlink_new_conntrack+0x3cf/0x7d0 nfnetlink_rcv_msg+0x48e/0x510 netlink_rcv_skb+0xc9/0x1f0 nfnetlink_rcv+0xdb/0x220 netlink_unicast+0x3ec/0x590 netlink_sendmsg+0x397/0x690 __sys_sendmsg+0xf4/0x180 Liberado por la tarea 0: slab_free_after_rcu_debug+0xad/0x1e0 rcu_core+0x5c3/0x9c0

14 Jul 2026, 13:18

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-019113.html -
  • () https://cert-portal.siemens.com/productcert/html/ssa-082556.html -

26 May 2026, 14:38

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/04c8907ce4e3d3e26c5e1a3e47aa5d17082cbb56 - () https://git.kernel.org/stable/c/04c8907ce4e3d3e26c5e1a3e47aa5d17082cbb56 - Patch
References () https://git.kernel.org/stable/c/5cb81eeda909dbb2def209dd10636b51549a3f8a - () https://git.kernel.org/stable/c/5cb81eeda909dbb2def209dd10636b51549a3f8a - Patch
References () https://git.kernel.org/stable/c/9821b47f669eb82791fa0b1a6ebaf9aa219bea72 - () https://git.kernel.org/stable/c/9821b47f669eb82791fa0b1a6ebaf9aa219bea72 - Patch
References () https://git.kernel.org/stable/c/bdf2724eefd4455a66863abb025bab8d3aa98c57 - () https://git.kernel.org/stable/c/bdf2724eefd4455a66863abb025bab8d3aa98c57 - Patch
References () https://git.kernel.org/stable/c/cd541f15b60e2257441398cf495d978f816d09f8 - () https://git.kernel.org/stable/c/cd541f15b60e2257441398cf495d978f816d09f8 - Patch
References () https://git.kernel.org/stable/c/d8cd0efbccc5cfb0a80da744a7da76e1333ab925 - () https://git.kernel.org/stable/c/d8cd0efbccc5cfb0a80da744a7da76e1333ab925 - Patch
References () https://git.kernel.org/stable/c/f025171feef2ac65663d7986f1d5ff0c28d6b2a9 - () https://git.kernel.org/stable/c/f025171feef2ac65663d7986f1d5ff0c28d6b2a9 - Patch
References () https://git.kernel.org/stable/c/f04cc86d59906513d2d62183b882966fc0ae0390 - () https://git.kernel.org/stable/c/f04cc86d59906513d2d62183b882966fc0ae0390 - Patch
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
CWE CWE-416

27 Apr 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

18 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/9821b47f669eb82791fa0b1a6ebaf9aa219bea72 -
  • () https://git.kernel.org/stable/c/d8cd0efbccc5cfb0a80da744a7da76e1333ab925 -

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 22:10


NVD link : CVE-2026-23458

Mitre link : CVE-2026-23458

CVE.ORG link : CVE-2026-23458


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free