CVE-2026-23274Disclosure(linux / linux_kernel)

HIGHCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer. If the label was created first by revision 1 with XT_IDLETIMER_ALARM, the object uses alarm timer semantics and timer->timer is never initialized. Reusing that object from revision 0 causes mod_timer() on an uninitialized timer_list, triggering debugobjects warnings and possible panic when panic_on_warn=1. Fix this by rejecting revision 0 rule insertion when an existing timer with the same label is of ALARM type.

7.5/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 1 mentions (2026-03-22); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Mentions · 2026-07-07: 1Mentions · 2026-08-13: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-09-12: 1PoC Mentioned / Linked · 2026-09-15: 1Exploit Tool / Code · 2026-07-07: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-09-15: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 1Technical Details · 2026-07-07: 1Technical Details · 2026-08-13: 1Technical Details · 2026-09-15: 103-2203-2307-0708-1309-1209-15
Signal classification4 categories
Disclosure
350.0%
PoC
116.7%
Active Exploitation
116.7%
Patch
116.7%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-231
Disclosure1
2026-07-071
PoC1
2026-08-131
Disclosure1
2026-09-121
Active Exploitation1
2026-09-151
Patch1
Full discourse6 posts
  • Mr. OS@ksg93rd
    Active Exploitation

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The tweet aggregates multiple 2026 CVEs, noting that MikroTik RouterOS vulnerabilities are actively exploited, yet it offers limited technical detail, PoC references, or patch information.

    01052600
    3.4K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-23274 PT ID: PT-2026-26579 Vendor: Linux Product: Linux Description: The Linux kernel contains an issue within the netfilter module, specifically in the xt IDLETIMER component. The problem arises from the reuse of ALARM timer labels by IDLETIMER revision 0 rules, which call mod timer() on an uninitialized timer list (timer->timer) if the label was initially created by revision 1 with XT IDLETIMER ALARM. This can lead to debugobjects warnings and potentially a system panic when panic on warn=1. The issue is addressed by preventing the insertion of revision 0 rules when an existing timer with the same label is of the ALARM type. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-26579 • https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-23274 #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2026-23274 has been released with detailed technical information and a GitHub repository, but no evidence of active exploitation or patches is provided.

    00043905
    3.4K followersView on X
  • Threat Landscape@LandscapeThreat
    Patch

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    The text discloses a Linux kernel local privilege-escalation vulnerability (CVE-2026-43502) and notes that it has been fixed by a specific commit included in Linux v7.1-rc3, while also mentioning that public exploits are available for the listed vulnerabilities.

    0002055
    98 followersView on X
  • Open-source Projects@the_osps
    Disclosure

    • GhostLock: a 15-year-old stack-UAF affecting all Linux distributions • Longinus: CVE-2026-6307 piercing Chrome's renderer and V8 sandbox • Netfilter bug CVE-2026-23274 exploited for a $10,500 kernelCTF bounty

    Post summary

    The text announces three new vulnerabilities, provides high‑level technical details, but lacks evidence of PoC, exploit code, active wild exploitation, or patch information.

    1000072
    1.6K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🧨 Another tiny kernel “label reuse” bug, another big faceplant. If timer internals aren’t initialized, congrats—your firewall rules become a kernel panic button. https://windowsforum.com/threads/cve-2026-23274-xt_idletimer-timer-label-reuse-can-trigger-kernel-panic.406500/ #LinuxKernelSecurity #NetfilterXtIdletimer #KernelPanicOnWarn #TimerLifecycleBug https://t.co/HzfwQAriUf

    Post summary

    The post discloses CVE‑2026‑23274, a kernel label reuse flaw causing timer‑related panic when internals are uninitialized, and signals a potential system crash via firewall rules.

    000002
    1.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23274 In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reus… https://www.cve.org/CVERecord?id=CVE-2026-23274

    Post summary

    The post announces that CVE-2026-23274, a netfilter timer-label reuse issue in the Linux kernel, has been resolved, but provides no PoC, exploit, or patch details.

    00000146
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more