cbcvebase.
CVE-2026-23274
published 2026-03-20

CVE-2026-23274: In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.4th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer. If the label was created first by revision 1 with XT_IDLETIMER_ALARM, the object uses alarm timer semantics and timer->timer is never initialized. Reusing that object from revision 0 causes mod_timer() on an uninitialized timer_list, triggering debugobjects warnings and possible panic when panic_on_warn=1. Fix this by rejecting revision 0 rule insertion when an existing timer with the same label is of ALARM type.

Affected

73 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= 68983a354a655c35d3fb204489d383a2a051fda7 < 32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa4432e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44
linuxlinux>= 68983a354a655c35d3fb204489d383a2a051fda7 < 144f88054ba0180467356f40895bd660b5dceeec144f88054ba0180467356f40895bd660b5dceeec
linuxlinux>= 68983a354a655c35d3fb204489d383a2a051fda7 < 28c7cfaf0c0ab17cbd7754092116fd1af45271f928c7cfaf0c0ab17cbd7754092116fd1af45271f9
linuxlinux>= 68983a354a655c35d3fb204489d383a2a051fda7 < 54080355999381fed4a26129579a5765bab8749154080355999381fed4a26129579a5765bab87491
linuxlinux>= 68983a354a655c35d3fb204489d383a2a051fda7 < 5e7ece24c5cb75a60402aad4d803c7898ea40aa95e7ece24c5cb75a60402aad4d803c7898ea40aa9
linuxlinux>= 68983a354a655c35d3fb204489d383a2a051fda7 < f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1
linuxlinux>= 68983a354a655c35d3fb204489d383a2a051fda7 < f228b9ae2a7e84d1153616d8e71c4236cb1f1309f228b9ae2a7e84d1153616d8e71c4236cb1f1309
linuxlinux>= 68983a354a655c35d3fb204489d383a2a051fda7 < 329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 5.7 < 5.10.2535.10.253
linuxlinux_kernel>= 5.7.0 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.196.18.19
linuxlinux_kernel>= 6.13.0 < 6.18.196.18.19
linuxlinux_kernel>= 6.19 < 6.19.96.19.9
linuxlinux_kernel>= 6.19.0 < 6.19.96.19.9
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.