PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23274 Linux CVE debrief

CVE-2026-23274 is a Linux kernel netfilter xt_IDLETIMER issue where revision 0 rules can reuse an existing timer by label even when that timer was first created by revision 1 with XT_IDLETIMER_ALARM. In that case, the reused object follows alarm-timer semantics and timer->timer is never initialized, yet rev0 still calls mod_timer() on it. The result can be debugobjects warnings and, if panic_on_warn=1 is enabled, a system panic. The kernel fix rejects rev0 rule insertion when an existing timer with the same label is an ALARM timer.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Linux kernel maintainers, distribution security teams, and operators running systems that use netfilter xt_IDLETIMER rules, especially where both revision 0 and revision 1 rule paths may be present.

Technical summary

The vulnerable path is label-based timer reuse in xt_IDLETIMER revision 0. If a label was previously created by revision 1 using XT_IDLETIMER_ALARM, the underlying object does not initialize timer->timer the way rev0 expects. Rev0 nevertheless reuses the object and invokes mod_timer() on that uninitialized timer_list. The documented fix is to block revision 0 rule insertion when the matching label already belongs to an ALARM timer.

Defensive priority

High priority for Linux kernel environments that expose xt_IDLETIMER rules, because the issue can cause kernel warnings and may escalate to a panic when panic_on_warn=1 is set.

Recommended defensive actions

  • Apply the Linux kernel fix that rejects revision 0 reuse of labels owned by XT_IDLETIMER_ALARM timers.
  • Review any netfilter/xt_IDLETIMER deployments for mixed revision 0 and revision 1 rule usage on the same labels.
  • Validate whether panic_on_warn=1 is enabled on affected systems, since the source description notes possible panic in that configuration.
  • Track vendor or distribution backports for the kernel stable commits referenced in the CVE record.
  • After patching, test rule insertion paths that reuse labels to confirm rev0 is correctly rejected for ALARM timers.

Evidence notes

This debrief is based on the CVE description and the official NVD/CVE record metadata supplied in the corpus. The source description states that revision 0 reuses timers by label, that ALARM timers leave timer->timer uninitialized for this path, and that the fix rejects rev0 insertion when the existing label is an ALARM timer. NVD lists the issue as CVE-2026-23274, published 2026-03-20 and modified 2026-04-18, with CVSS v3.1 vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and status 'Undergoing Analysis'.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23274 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23274

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23274 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23274

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/144f88054ba0180467356f40895bd660b5dceeec

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/28c7cfaf0c0ab17cbd7754092116fd1af45271f9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/54080355999381fed4a26129579a5765bab87491

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5e7ece24c5cb75a60402aad4d803c7898ea40aa9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f228b9ae2a7e84d1153616d8e71c4236cb1f1309

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.