Executive brief
A vulnerability exists in the Linux kernel's networking subsystem that could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when specific network traffic filtering rules are applied to outgoing data, leading to a memory error known as a 'use-after-free.' This could impact system stability and the confidentiality of data processed by the kernel.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's net/sched component due to improper binding of the act_ct action. When act_ct is attached to egress paths other than clsact, the packet classifier can return a TC_ACT_CONSUMED status while the socket buffer (skb) is still being held by the defragmentation engine. This leads to a UAF condition when the defragmentation engine subsequently attempts to access the packet. The fix restricts act_ct binding to clsact/ingress qdiscs and shared blocks, which correctly handle the TC_ACT_CONSUMED state. This vulnerability is reachable by a local user with sufficient privileges to configure network traffic control settings.
Affected products
- Linux Linux Kernel 5.15.148 to 5.15.203, 6.1.75 to 6.1.167, 6.6.14 to 6.6.130, 6.7.2 to 6.8, 6.8 to 6.12.77, 6.13 to 6.18.18, 6.19 to 6.19.8, 7.0-rc1, 7.0-rc2
Timeline
- 2026-03-18: advisory: Initial disclosure of CVE-2026-23270
- 2026-02-27: patched: Mainline kernel patch committed by Jakub Kicinski
References
- https://git.kernel.org/stable/c/11cb63b0d1a0685e0831ae3c77223e002ef18189
- https://git.kernel.org/stable/c/380ad8b7c65ea7aa10ef2258297079ed5ac1f5b6
- https://git.kernel.org/stable/c/524ce8b4ea8f64900b6c52b6a28df74f6bc0801e
- https://git.kernel.org/stable/c/5a110ddcc99bda77a28598b3555fe009eaab3828
- https://git.kernel.org/stable/c/9deda0fcda5c1f388c5e279541850b71a2ccfcf4
- https://git.kernel.org/stable/c/bc4e5bb529823a09f02dbe96169de679a9db26e0
- https://git.kernel.org/stable/c/fb3c380a54e33d1fd272cc342faa906d787d7ef1