oM noM Security Feeds cve
vulnerability context

CVE-2026-23274

CVSS 7.8 HIGHEPSS 6.3%OTX 6 pulses

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer. If the label was created first by revision 1 with XT_IDLETIMER_ALARM, the object uses alarm timer semantics and timer->timer is never initialized. Reusing that object from revision 0 causes mod_timer() on an uninitialized timer_list, triggering debugobjects warnings and possible panic when panic_on_warn=1. Fix this by rejecting revision 0 rule insertion when...

Published 2026-03-20 · last modified 2026-05-22

details

CISA KEV status
Not in catalog
CVSS v3
7.8 / HIGH
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
6.3% percentile (score 0.0002)
OTX pulses
6 total, 0 recent

source mentions 3

source consensus

  • Ubuntu Security Notices
Want the 3-bullet summary of CVE-2026-23274, plus webhook alerts when KEV is updated? Pro is $10/mo.