CVE-2026-23393Patch(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletion When a peer MEP is being deleted, cancel_delayed_work_sync() is called on ccm_rx_dwork before freeing. However, br_cfm_frame_rx() runs in softirq context under rcu_read_lock (without RTNL) and can re-schedule ccm_rx_dwork via ccm_rx_timer_start() between cancel_delayed_work_sync() returning and kfree_rcu() being called. The following is a simple race scenario: cpu0 cpu1 mep_delete_implementation() cancel_delayed_work_sync(ccm_rx_dwork); br_cfm_frame_rx() // peer_mep still in hlist if (peer_mep->ccm_defect) ccm_rx_timer_start() queue_delayed_work(ccm_rx_dwork) hlist_del_rcu(&peer_mep->head); kfree_rcu(peer_mep, rcu); ccm_rx_work_expired() // on freed peer_mep To prevent this, cancel_delayed_work_sync() is replaced with disable_delayed_work_sync() in both peer MEP deletion paths, so that subsequent queue_delayed_work() calls from br_cfm_frame_rx() are silently rejected. The cc_peer_disable() helper retains cancel_delayed_work_sync() because it is also used for the CC enable/disable toggle path where the work must remain re-schedulable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-25: 3Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-25: 2Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 103-2503-2603-27
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-253
Disclosure1Patch2
2026-03-261
Patch1
2026-03-271
Disclosure1
Full discourse5 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-23393 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23393 #CVE-2026-23393 #CVE   #CyberSecurity #InfoSec https://t.co/9AF1UZxsE9

    Post summary

    A brief alert announcing CVE‑2026‑23393 with unknown risk level and unspecified affected products, referencing the NVD entry.

    0000031
    123 followersView on X
  • WindowsForum@windowsforum
    Patch

    😈 Another race “fix” by disabling delayed work—because timing bugs love becoming use-after-free parties. This is why security patches should ship with a seatbelt for your kernel! #WindowsForum https://windowsforum.com/threads/cve-2026-23393-fix-disable-delayed-work-to-close-a-bridge-cfm-race.407449/ #RaceCondition #DelayedWork #LinuxKernelSecurity #BridgeCfm https://t.co/XuWJIXyb2p

    Post summary

    The thread announces a patch for CVE‑2026‑23393, a race condition leading to a use‑after‑free error, and suggests disabling delayed work as a mitigation.

    0000021
    1.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-23393 - bridge: cfm: Fix race condition in peer_mep deletion Intel Report: https://ift.tt/mUZn8Nr

    Post summary

    The alert announces CVE-2026-23393, a race condition in bridge:cfm’s peer_mep deletion, and links to an intel report, but it does not include PoC, exploit code, active exploitation, or patch information.

    0000035
    286 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-23393 In the Linux kernel, the following vulnerability has been resolved: bridge https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23393

    Post summary

    The post announces that CVE-2026-23393 in the Linux kernel’s bridge component has been resolved, indicating a patch is available, but it provides no technical details or exploitation information.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23393 In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletion When a peer MEP is being deleted, cancel_de… https://www.cve.org/CVERecord?id=CVE-2026-23393

    Post summary

    The CVE‑2026‑23393 race‑condition issue in the Linux kernel has been fixed; no PoC or exploitation details are provided.

    0000062
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.11--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more