CVE-2026-23239PoC(linux / linux_kernel)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths such as the Delayed ACK handler or ksoftirqd. As a result, the espintcp_tx_work() worker may dereference a freed espintcp ctx or sk. The following is a simple race scenario: cpu0 cpu1 espintcp_close() cancel_work_sync(&ctx->work); espintcp_write_space() schedule_work(&ctx->work); To prevent this race condition, cancel_work_sync() is replaced with disable_work_sync().

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Peaked 4d ago at 1 mentions (2026-03-16); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-16: 1Mentions · 2026-03-23: 1Mentions · 2026-03-25: 1Mentions · 2026-09-25: 1Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-09-25: 1Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-03-25: 1Exploit Tool / Code · 2026-09-25: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-25: 1Technical Details · 2026-09-25: 103-1603-2303-2509-2510-02
Signal classification3 categories
PoC
250.0%
Patch
125.0%
Exploit
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-161
Patch1
2026-03-231
PoC1
2026-03-251
Exploit1
2026-09-251
PoC1
Full discourse5 posts
  • V4bel@v4bel
    PoC

    I discovered a race-based vulnerability class in the Linux kernel: "Out-of-Cancel" A structural flaw where cancel_work_sync() is used as a barrier for object lifetime management, causing UAF across multiple networking subsystems. I wrote an exploit for CVE-2026-23239 (espintcp). It interleaves Delayed ACK timers, NET_RX softirqs, timerfd hardirqs, workqueue scheduling, and CFS scheduler manipulation to hit a ~Xµs race window. Blog: https://v4bel.github.io/linux/2026/03/23/ooc.html This is the race scenario diagram 😁:

    Post summary

    The post announces a race-based vulnerability in the Linux kernel and presents a proof‑of‑concept exploit, detailing the technical aspects but not reporting active attacks or patches.

    666235521932.2K
    1.5K followersView on X
  • Hermes Tool@Hermes_tooll
    Exploit

    race-based vulnerability class in the Linux kernel: "Out-of-Cancel" A structural flaw where cancel_work_sync() is used as a barrier for object lifetime management, causing UAF across multiple networking subsystems. I wrote an exploit for CVE-2026-23239 (espintcp). It interleaves Delayed ACK timers, NET_RX softirqs, timerfd hardirqs, workqueue scheduling, and CFS scheduler manipulation to hit a ~Xµs race window. Blog: https://v4bel.github.io/linux/2026/03/23/ooc.html This is the race scenario diagram 😁:

    Post summary

    The post discloses a race‑based use‑after‑free flaw (CVE‑2026‑23239) in the Linux kernel and demonstrates a crafted exploit that manipulates kernel timing primitives to trigger the bug. No evidence of active exploitation or mitigation is provided.

    0201961.2K
    3.0K followersView on X
  • !Manan@0xManan

    No caps. No fancy gadget. Unprivileged local → uid 0. RustyTux / CVE-2026-23239: ESP-in-TCP strparser UAF race. Chain: receive parser overlaps socket teardown → rearms `msg_timer_work` after `strp_done()` → reclaim `espintcp_ctx` → flip `modprobe_path` → root. Stock CentOS Stream 9 / Ubuntu 26.04 kernels. Public PoC w/ KASLR prefetch leak. Tip: https://github.com/m0x41nos/RustyTux Bookmark if you live in kernel land. #Linux #LPE #CVE

    00030327
    2.2K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    RustyTux is a public PoC for a Linux kernel privilege escalation via an ESP-in-TCP use-after-free (CVE-2026-23239). Details and exploit code are now public. #RustyTux #LinuxKernel #PrivilegeEscalation #UseAfterFree #espintcp #LPE #PoC #CVE202623239 https://securityonline.info/rustytux-linux-kernel-lpe-poc/

    Post summary

    The text announces the availability of a public PoC (RustyTux) for a Linux kernel privilege escalation vulnerability (CVE-2026-23239), along with exploit code and technical details, without mentioning active exploitation or patches.

    00020500
    13.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23239 In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. … https://www.cve.org/CVERecord?id=CVE-2026-23239

    Post summary

    CVE‑2026‑23239 is a race‑condition vulnerability in the Linux kernel’s espintcp_close function that has been fixed; no PoC, active exploitation, or false‑positive claims are mentioned.

    00000179
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--

Explore more