PT-2026-26583 · Linux · Linux Kernel
Publicado
2026-01-01
·
Atualizado
2026-05-26
·
CVE-2026-23278
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains an issue within the netfilter subsystem related to nf tables. During transaction processing, multiple catchall elements may exist, including one active and one pending from a new batch. If the map containing these catchall elements is being removed, all catchall elements must be toggled, not just the first viable candidate. Failure to do so can lead to a warning related to
nft data release and potential issues with element destruction and transaction handling. The issue involves the nft data release function and impacts the processing of catchall elements within nf tables.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux Kernel