cbcvebase.
CVE-2026-23412
published 2026-04-02

CVE-2026-23412: In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qian reports…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qian reports UaF when concurrent process is dumping hooks via nfnetlink_hooks: BUG: KASAN: slab-use-after-free in nfnl_hook_dump_one.isra.0+0xe71/0x10f0 Read of size 8 at addr ffff888003edbf88 by task poc/79 Call Trace: nfnl_hook_dump_one.isra.0+0xe71/0x10f0 netlink_dump+0x554/0x12b0 nfnl_hook_get+0x176/0x230 [..] Defer release until after concurrent readers have completed.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= 84601d6ee68ae820dec97450934797046d62db4b < d016c216bc75c45128160593a77b864a04dbe7c0d016c216bc75c45128160593a77b864a04dbe7c0
linuxlinux>= 84601d6ee68ae820dec97450934797046d62db4b < cb2bf5efdb02a2a59faf603604a1066e8266f349cb2bf5efdb02a2a59faf603604a1066e8266f349
linuxlinux>= 84601d6ee68ae820dec97450934797046d62db4b < c25e0dec366ae99b7264324ce3c7cbaea34691f9c25e0dec366ae99b7264324ce3c7cbaea34691f9
linuxlinux>= 84601d6ee68ae820dec97450934797046d62db4b < 54244d54a971c26a0cd0a9073460ff71f3c51b3254244d54a971c26a0cd0a9073460ff71f3c51b32
linuxlinux>= 84601d6ee68ae820dec97450934797046d62db4b < 24f90fa3994b992d1a09003a3db2599330a5232a24f90fa3994b992d1a09003a3db2599330a5232a
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.4.1 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-aws
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.