CVE-2026-23274

Source
https://cve.org/CVERecord?id=CVE-2026-23274
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23274.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23274
Downstream
Related
Published
2026-03-20T08:08:54.918Z
Modified
2026-04-16T08:44:14.722571634Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels

IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer.

If the label was created first by revision 1 with XTIDLETIMERALARM, the object uses alarm timer semantics and timer->timer is never initialized. Reusing that object from revision 0 causes modtimer() on an uninitialized timerlist, triggering debugobjects warnings and possible panic when paniconwarn=1.

Fix this by rejecting revision 0 rule insertion when an existing timer with the same label is of ALARM type.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23274.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
68983a354a655c35d3fb204489d383a2a051fda7
Fixed
28c7cfaf0c0ab17cbd7754092116fd1af45271f9
Fixed
54080355999381fed4a26129579a5765bab87491
Fixed
5e7ece24c5cb75a60402aad4d803c7898ea40aa9
Fixed
f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1
Fixed
f228b9ae2a7e84d1153616d8e71c4236cb1f1309
Fixed
329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23274.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
6.1.167
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.19
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23274.json"