CVE-2026-23231Patch(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add()) before registering hooks. If nf_tables_register_hook() then fails, the error path calls nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy() with no RCU grace period in between. This creates two use-after-free conditions: 1) Control-plane: nf_tables_dump_chains() traverses table->chains under rcu_read_lock(). A concurrent dump can still be walking the chain when the error path frees it. 2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly installs the IPv4 hook before IPv6 registration fails. Packets entering nft_do_chain() via the transient IPv4 hook can still be dereferencing chain->blob_gen_X when the error path frees the chain. Add synchronize_rcu() between nft_chain_del() and the chain destroy so that all RCU readers -- both dump threads and in-flight packet evaluation -- have finished before the chain is freed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-04: 3Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-04: 203-04
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-23231 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes … https://www.cve.org/CVERecord?id=CVE-2026-23231 ----- Traducción: CVE-2026-23231 En … http://infoflow.cloud`

    Post summary

    The Linux kernel nf_tables use‑after‑free vulnerability CVE‑2026‑23231 has been resolved, but the text offers only a high‑level statement of the fix without providing patch details or PoC information.

    0000037
    55 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23231 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes … https://www.cve.org/CVERecord?id=CVE-2026-23231

    Post summary

    The Linux kernel vulnerability CVE-2026-23231, a use‑after‑free in nf_tables_addchain, has been resolved, implying a patch is available, but no PoC, exploit, or active exploitation details are provided.

    00000171
    56.6K followersView on X
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting Linux Kernel (CVE-2026-23231) https://vuldb.com/?id.348710

    Post summary

    The post announces the addition of a Linux Kernel vulnerability (CVE‑2026‑23231) and links to a database entry, without providing technical details, patches, or exploitation information.

    0000061
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more