HIGHCVE-2026-23274Published Modified CNA Linux
CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer. If the label was created first by revision 1 with XT_IDLETIMER_ALARM, the object uses alarm timer semantics and timer->timer is never initialized. Reusing that object from revision 0 causes mod_timer() on an uninitialized timer_list, triggering debugobjects warnings and possible panic when panic_on_warn=1. Fix this by rejecting revision 0 rule insertion when an existing timer with the same label is of ALARM type.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
0144f88054ba0180467356f40895bd660b5dceeec28c7cfaf0c0ab17cbd7754092116fd1af45271f9329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa445.10.2535.15.20354080355999381fed4a26129579a5765bab874915e7ece24c5cb75a60402aad4d803c7898ea40aa96.1.1676.6.1306.12.786.18.196.19.97.0f228b9ae2a7e84d1153616d8e71c4236cb1f1309f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1
Affected packages
- Linux / Linux< 32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44 (from 68983a354a655c35d3fb204489d383a2a051fda7) · < 144f88054ba0180467356f40895bd660b5dceeec (from 68983a354a655c35d3fb204489d383a2a051fda7) · < 28c7cfaf0c0ab17cbd7754092116fd1af45271f9 (from 68983a354a655c35d3fb204489d383a2a051fda7) · < 54080355999381fed4a26129579a5765bab87491 (from 68983a354a655c35d3fb204489d383a2a051fda7) · < 5e7ece24c5cb75a60402aad4d803c7898ea40aa9 (from 68983a354a655c35d3fb204489d383a2a051fda7) · < f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1 (from 68983a354a655c35d3fb204489d383a2a051fda7)
- Linux / Linux5.7Fixed in 0, 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.19, 6.19.9, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H