Junglewise Threat Intelligence

CVE-2026-23274: Linux Kernel denial of service in Netfilter xt_IDLETIMER

CVE-2026-23274 · Severity: high · CVSS 7.8 · Published 2026-03-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue occurs when the system's firewall component (Netfilter) incorrectly handles certain types of network idle timers. An attacker with local access could exploit this to cause a kernel panic, leading to a complete service outage.

Technical details

A vulnerability exists in the xt_IDLETIMER module of the Linux kernel's Netfilter subsystem. Revision 0 rules in IDLETIMER attempt to reuse existing timers by label and unconditionally call mod_timer() on the timer object. If a label was previously created as an ALARM type (Revision 1), the standard timer list is never initialized. A local attacker can trigger a call to mod_timer() on this uninitialized timer_list, resulting in a kernel panic (especially if panic_on_warn is enabled). The fix involves rejecting Revision 0 rule insertions if an existing timer with the same label is of the ALARM type.

Affected products

  • Linux Linux kernel 5.7 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1 to 7.0-rc3

Timeline

  • 2026-03-09: other: Patch authored
  • 2026-03-20: disclosed
  • 2026-03-20: advisory

References

Related threats