Executive brief
A vulnerability exists in the Linux kernel's networking subsystem (Netfilter) that could allow a local user to cause a system crash or potentially gain unauthorized privileges. The issue occurs when the system handles firewall rule sets that have reached their maximum capacity. By exploiting a timing flaw in how the kernel manages memory for these rules, an attacker could trigger a memory safety error.
Technical details
A race condition exists in net/netfilter/nf_tables_api.c within the nft_add_set_elem function. When a set is full, a new element could be published and then immediately removed without waiting for the RCU (Read-Copy-Update) grace period. This allows an RCU reader to continue accessing the element after it has been freed, leading to a use-after-free vulnerability. The fix involves unconditionally incrementing the element count (set->nelems) before insertion and using a flag to trigger a safe abort path if the set is full, ensuring proper synchronization. The vulnerability is reachable by local users with sufficient permissions to manipulate nf_tables.
Affected products
- Linux Linux Kernel 4.9.33 to 4.10, 4.10.1 to 6.18.17, 6.19 to 6.19.7
Timeline
- 2026-03-20: disclosed: Initial disclosure of CVE-2026-23272
- 2026-03-05: patched: Mainline kernel patch committed
- 2026-03-20: advisory