Junglewise Threat Intelligence

CVE-2026-23270: Linux Kernel use-after-free in net/sched act_ct action

CVE-2026-23270 · Severity: high · CVSS 7.8 · Published 2026-03-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's networking subsystem that could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when specific network traffic filtering rules are applied to outgoing data, leading to a memory error known as a 'use-after-free.' This could impact system stability and the confidentiality of data processed by the kernel.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel's net/sched component due to improper binding of the act_ct action. When act_ct is attached to egress paths other than clsact, the packet classifier can return a TC_ACT_CONSUMED status while the socket buffer (skb) is still being held by the defragmentation engine. This leads to a UAF condition when the defragmentation engine subsequently attempts to access the packet. The fix restricts act_ct binding to clsact/ingress qdiscs and shared blocks, which correctly handle the TC_ACT_CONSUMED state. This vulnerability is reachable by a local user with sufficient privileges to configure network traffic control settings.

Affected products

  • Linux Linux Kernel 5.15.148 to 5.15.203, 6.1.75 to 6.1.167, 6.6.14 to 6.6.130, 6.7.2 to 6.8, 6.8 to 6.12.77, 6.13 to 6.18.18, 6.19 to 6.19.8, 7.0-rc1, 7.0-rc2

Timeline

  • 2026-03-18: advisory: Initial disclosure of CVE-2026-23270
  • 2026-02-27: patched: Mainline kernel patch committed by Jakub Kicinski

References

Related threats