CVE-2026-23412

Source
https://cve.org/CVERecord?id=CVE-2026-23412
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23412.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23412
Downstream
Related
Published
2026-04-02T11:40:53.528Z
Modified
2026-07-15T01:48:54.791743647Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
netfilter: bpf: defer hook memory release until rcu readers are done
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: bpf: defer hook memory release until rcu readers are done

Yiming Qian reports UaF when concurrent process is dumping hooks via nfnetlink_hooks:

BUG: KASAN: slab-use-after-free in nfnlhookdumpone.isra.0+0xe71/0x10f0 Read of size 8 at addr ffff888003edbf88 by task poc/79 Call Trace: <TASK> nfnlhookdumpone.isra.0+0xe71/0x10f0 netlinkdump+0x554/0x12b0 nfnlhook_get+0x176/0x230 [..]

Defer release until after concurrent readers have completed.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23412.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
84601d6ee68ae820dec97450934797046d62db4b
Fixed
d016c216bc75c45128160593a77b864a04dbe7c0
Fixed
cb2bf5efdb02a2a59faf603604a1066e8266f349
Fixed
c25e0dec366ae99b7264324ce3c7cbaea34691f9
Fixed
54244d54a971c26a0cd0a9073460ff71f3c51b32
Fixed
24f90fa3994b992d1a09003a3db2599330a5232a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23412.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.20
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23412.json"