CVE-2026-23351General(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: split gc into unlink and reclaim phase Yiming Qian reports Use-after-free in the pipapo set type: Under a large number of expired elements, commit-time GC can run for a very long time in a non-preemptible context, triggering soft lockup warnings and RCU stall reports (local denial of service). We must split GC in an unlink and a reclaim phase. We cannot queue elements for freeing until pointers have been swapped. Expired elements are still exposed to both the packet path and userspace dumpers via the live copy of the data structure. call_rcu() does not protect us: dump operations or element lookups starting after call_rcu has fired can still observe the free'd element, unless the commit phase has made enough progress to swap the clone and live pointers before any new reader has picked up the old version. This a similar approach as done recently for the rbtree backend in commit 35f83a75529a ("netfilter: nft_set_rbtree: don't gc elements on insert").

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 103-2503-2603-27
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
General1
2026-03-261
Patch1
2026-03-271
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-23351 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23351 #CVE-2026-23351 #CVE   #CyberSecurity #InfoSec https://t.co/eHxnc4g4SP

    Post summary

    A tweet simply announces CVE-2026-23351 with an unknown risk level and no further technical or mitigation details.

    0000031
    123 followersView on X
  • WindowsForum@windowsforum
    Patch

    🧨 Linux kernel netfilter is patching a use-after-free in nft_set_pipapo with proper GC reordering—because “fix later” is a fun game… for the crash log. #CVE #LinuxKernel https://windowsforum.com/threads/cve-2026-23351-fix-nft_set_pipapo-use-after-free-and-local-dos-in-linux-kernel.407383/ #LinuxKernel #UseAfterFree #Nftables #NetfilterSecurity

    Post summary

    The post announces that the Linux kernel team has applied a patch to fix a use‑after‑free in nft_set_pipapo, giving a brief technical description but providing no PoC or exploitation details.

    0000027
    1.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-23351 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: split gc into unlink and reclaim phase Yiming Qian reports Use-after-… https://www.cve.org/CVERecord?id=CVE-2026-23351

    Post summary

    The CVE-2026-23351 in the Linux kernel has been resolved, but the post provides no proof‑of‑concept, exploit code, active exploitation evidence, or patch details.

    00000116
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.6--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more