CVE-2026-23272Time-of-check Time-of-use (TOCTOU) Race Condition in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 97.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 20

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally bump set->nelems before insertion In case that the set is full, a new element gets published then removed without waiting for the RCU grace period, while RCU reader can be walking over it already. To address this issue, add the element transaction even if set is full, but toggle the set_full flag to report -ENFILE so the abort path safely unwinds the set to its previous state. As for ele

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Linuxlinux/linux_kernel4.10.06.18.17+1
Debianlinux/linux_kernel< 6.19.8-1
CVEListV5linux/linux35d0ac9070ef619e3bf44324375878a1c540387b6826131c7674329335ca25df2550163eb8a1fd0c+4

🔴Vulnerability Details

4
CVEList
netfilter: nf_tables: unconditionally bump set->nelems before insertion2026-03-20
OSV
netfilter: nf_tables: unconditionally bump set->nelems before insertion2026-03-20
OSV
CVE-2026-23272: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally bump set->nelems before insertion In case th2026-03-20
GHSA
GHSA-qhvv-4mw5-pxh3: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally bump set->nelems before insertion In case2026-03-20

📋Vendor Advisories

3
Red Hat
kernel: netfilter: nf_tables: unconditionally bump set->nelems before insertion2026-03-20
Microsoft
netfilter: nf_tables: unconditionally bump set->nelems before insertion2026-03-10
Debian
CVE-2026-23272: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23272 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23272 — Linux vulnerability | cvebase