CVE-2026-23270Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks As Paolo said earlier [1]: "Since the blamed commit below, classify can return TC_ACT_CONSUMED while the current skb being held by the defragmentation engine. As reported by GangMin Kim, if such packet is that may cause a UaF when the defrag engine later on tries to tuch again such packet." act_ct was never meant to be used in the egress path, however some users are attaching it to egress today [2]. Attempting to reach a middle ground, we noticed that, while most qdiscs are not handling TC_ACT_CONSUMED, clsact/ingress qdiscs are. With that in mind, we address the issue by only allowing act_ct to bind to clsact/ingress qdiscs and shared blocks. That way it's still possible to attach act_ct to egress (albeit only with clsact). [1] https://lore.kernel.org/netdev/674b8cbfc385c6f37fb29a1de08d8fe5c2b0fbee.1771321118.git.pabeni@redhat.com/ [2] https://lore.kernel.org/netdev/[email protected]/

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-18: 2Mentions · 2026-04-26: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 1Technical Details · 2026-04-26: 103-1804-26
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1Patch1
2026-04-261
General1
Full discourse3 posts
  • IntegSec@integ_sec
    General

    CVE-2026-23270: Linux Kernel Traffic Control Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04dsYdq0

    Post summary

    The post highlights CVE-2026-23270, a Linux Kernel traffic control bug, and outlines its business implications and response guidelines, but does not provide detailed exploit, patch, or PoC information.

    0000045
    30 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23270 In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks As Paolo said ea… https://www.cve.org/CVERecord?id=CVE-2026-23270

    Post summary

    The post notes that CVE‑2026‑23270, a Linux kernel network scheduler issue, has been fixed with a patch—no exploit or PoC is mentioned, and there is no evidence of active exploitation.

    0000074
    56.8K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-23270) https://vuldb.com/?id.351556

    Post summary

    The text announces the existence of a newly identified critical Linux kernel vulnerability (CVE-2026-23270) with a reference to a vulnerability database, but does not provide technical, exploit, or remediation details.

    0000082
    2.1K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more