7.8

CVE-2026-23274

netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels

IDLETIMER revision 0 rules reuse existing timers by label and always call
mod_timer() on timer->timer.

If the label was created first by revision 1 with XT_IDLETIMER_ALARM,
the object uses alarm timer semantics and timer->timer is never initialized.
Reusing that object from revision 0 causes mod_timer() on an uninitialized
timer_list, triggering debugobjects warnings and possible panic when
panic_on_warn=1.

Fix this by rejecting revision 0 rule insertion when an existing timer with
the same label is of ALARM type.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 68983a354a655c35d3fb204489d383a2a051fda7
Version < 32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44
Status affected
Version 68983a354a655c35d3fb204489d383a2a051fda7
Version < 144f88054ba0180467356f40895bd660b5dceeec
Status affected
Version 68983a354a655c35d3fb204489d383a2a051fda7
Version < 28c7cfaf0c0ab17cbd7754092116fd1af45271f9
Status affected
Version 68983a354a655c35d3fb204489d383a2a051fda7
Version < 54080355999381fed4a26129579a5765bab87491
Status affected
Version 68983a354a655c35d3fb204489d383a2a051fda7
Version < 5e7ece24c5cb75a60402aad4d803c7898ea40aa9
Status affected
Version 68983a354a655c35d3fb204489d383a2a051fda7
Version < f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1
Status affected
Version 68983a354a655c35d3fb204489d383a2a051fda7
Version < f228b9ae2a7e84d1153616d8e71c4236cb1f1309
Status affected
Version 68983a354a655c35d3fb204489d383a2a051fda7
Version < 329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 5.10.*
Version 5.10.253
Status unaffected
Version <= 5.15.*
Version 5.15.203
Status unaffected
Version <= 6.1.*
Version 6.1.167
Status unaffected
Version <= 6.6.*
Version 6.6.130
Status unaffected
Version <= 6.12.*
Version 6.12.78
Status unaffected
Version <= 6.18.*
Version 6.18.19
Status unaffected
Version <= 6.19.*
Version 6.19.9
Status unaffected
Version <= *
Version 7.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.