Junglewise Threat Intelligence

CVE-2026-23278: Linux Kernel nf_tables improper element handling in netfilter

CVE-2026-23278 · Severity: high · CVSS 7.8 · Published 2026-03-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem, specifically within the netfilter component used for firewalling and packet filtering. An attacker with local access could exploit this flaw to cause a system crash or potentially gain unauthorized elevated privileges. This issue stems from how the system handles certain firewall rules during configuration updates, leading to memory management errors.

Technical details

A vulnerability exists in the nf_tables component of the Linux kernel netfilter subsystem. During transaction processing, the kernel may fail to iterate through all pending 'catchall' elements when a map is being removed. Specifically, the nft_map_catchall_deactivate and nft_map_catchall_activate functions contained 'break' statements that caused the loop to exit after processing only the first viable candidate, even if multiple elements (e.g., one live and one pending) were present. This logic error can lead to incorrect reference counting or state management, resulting in a use-after-free or similar memory corruption during transaction aborts. The issue is reachable via local netlink batch requests and has been patched in multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 4.19.316 to 4.20, 5.4.262 to 5.5, 5.10.188 to 5.11, 5.15.121 to 5.16, 6.1.36 to 6.2, 6.3.10 to 6.4, 6.4.1 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9

Timeline

  • 2026-03-05: other: Patch authored
  • 2026-03-20: disclosed
  • 2026-03-20: advisory

References

Related threats