PatchSiren cyber security CVE debrief
CVE-2026-23270 Linux CVE debrief
CVE-2026-23270 is a Linux kernel networking issue in net/sched affecting act_ct. The kernel fix restricts act_ct so it can bind only to clsact/ingress qdiscs and shared blocks, while still allowing clsact-based egress use. The underlying concern is a use-after-free scenario where classify can return TC_ACT_CONSUMED while the skb is still held by the defragmentation engine, and the packet may later be touched again.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-18
- Original CVE updated
- 2026-04-18
- Advisory published
- 2026-03-18
- Advisory updated
- 2026-04-18
Who should care
Linux kernel maintainers, distro security teams, and operators using tc/traffic-control configurations with act_ct, especially on systems where local users can influence qdisc or filter setup. Security teams should treat this as a kernel memory-corruption issue with local exploitation potential.
Technical summary
Per the supplied kernel description, act_ct was not intended for the egress path, but some deployments attached it there. The fix narrows where act_ct may bind: only clsact/ingress qdiscs and shared blocks are allowed. This matters because classify can return TC_ACT_CONSUMED while the current skb is still owned by the defragmentation engine; if that skb is touched again later, a use-after-free may occur. The official CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, consistent with a local, low-privilege, high-impact kernel issue.
Defensive priority
High. The CVSS 7.8 rating and high confidentiality/integrity/availability impact make this a priority kernel fix, especially for hosts using tc with act_ct. Update to kernels containing the restriction and review any non-clsact act_ct deployments.
Recommended defensive actions
- Apply the kernel update or backport that restricts act_ct to clsact/ingress qdiscs and shared blocks.
- Audit tc configurations for act_ct on non-clsact qdiscs or unexpected egress placements.
- Verify any automation or orchestration that creates traffic-control rules does not depend on unsupported act_ct bindings.
- Prioritize patching hosts where local users can influence network qdisc or filter configuration.
- Monitor vendor advisories and backport status for your kernel branch.
Evidence notes
The vulnerability description and fix scope come from the supplied CVE text. NVD metadata lists CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and references multiple kernel stable commit links. The NVD record was still marked 'Undergoing Analysis' at the supplied modified date.
Official resources
-
CVE-2026-23270 CVE record
CVE.org
-
CVE-2026-23270 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Publicly disclosed in the supplied CVE record on 2026-03-18; modified on 2026-04-18. The corpus does not provide a strong product/vendor attribution, so this debrief treats it as a Linux kernel issue rather than a product-specific advisory.