CVE-2026-23392General(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flowtable after rcu grace period on error Call synchronize_rcu() after unregistering the hooks from error path, since a hook that already refers to this flowtable can be already registered, exposing this flowtable to packet path and nfnetlink_hook control plane. This error path is rare, it should only happen by reaching the maximum number hooks or by failing to set up to hardware offload, just call synchronize_rcu(). There is a check for already used device hooks by different flowtable that could result in EEXIST at this late stage. The hook parser can be updated to perform this check earlier to this error path really becomes rarely exercised. Uncovered by KASAN reported as use-after-free from nfnetlink_hook path when dumping hooks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Patch: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 103-2503-2603-27
Signal classification3 categories
General
360.0%
Patch
120.0%
Disclosure
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-252
General1Patch1
2026-03-262
Disclosure1General1
2026-03-271
General1
Full discourse5 posts
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-23392) https://vuldb.com/?id.353106

    Post summary

    The text announces a new critical Linux Kernel CVE (CVE-2026-23392) but provides no additional technical, exploit, or mitigation details.

    0101185
    2.1K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23392 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23392 #CVE-2026-23392 #CVE   #CyberSecurity #InfoSec https://t.co/0OfHiTIEvu

    Post summary

    The tweet serves merely to announce CVE‑2026‑23392 and link to its NVD page, offering no further context or actionable information.

    0000028
    123 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🦂 Linux’s nf_tables got a use-after-free because teardown happened before the RCU grace period. “Narrow bug,” sure—until your kernel starts double-freeing reality. https://windowsforum.com/threads/cve-2026-23392-nf_tables-flowtable-use-after-free-and-the-rcu-grace-fix.407410/ #LinuxKernelSecurity #UseAfterFree #NetfilterNfTables #RcuSynchronize https://t.co/mivijIpiUe

    Post summary

    The post reveals details of a kernel use‑after‑free vulnerability (CVE‑2026‑23392) in nf_tables, but it does not mention PoC, exploit code, active exploitation, or patching information.

    0000033
    1.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-23392 - netfilter: nf_tables: release flowtable after rcu grace period on error Intel Report: https://ift.tt/H0avIgn

    Post summary

    An alert referencing CVE-2026-23392 with a brief technical description is issued, but no PoC, exploit code, active exploitation, patch, or debunk statement is provided.

    0000042
    286 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23392 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flowtable after rcu grace period on error Call synchronize_rcu() a… https://www.cve.org/CVERecord?id=CVE-2026-23392

    Post summary

    The note indicates that CVE‑2026‑23392, affecting Linux kernel nf_tables, has been fixed, though no explicit patch details or mitigation steps are provided.

    0000066
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel4.16--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more