PatchSiren cyber security CVE debrief
CVE-2026-23391 Linux CVE debrief
A vulnerability has been resolved in the Linux kernel related to netfilter: xt_CT. Templates refer to objects that can go away while packets are sitting in nfqueue. This can cause issues on module removal or timeout policy removal. The use of templates with zone and event cache filter are safe, since this just copies values. However, to prevent potential issues, enqueued packets should be flushed in case the template rule gets removed. This issue can have a significant operational impact if not addressed.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Users of the Linux kernel who utilize netfilter: xt_CT may be affected by this vulnerability. It is recommended to review the affected versions and apply patches as necessary. Affected operators should assess their platform vulnerability and security teams should prioritize patching.
Technical summary
The Linux kernel vulnerability CVE-2026-23391 is related to the netfilter: xt_CT component. The vulnerability arises from the use of templates that refer to objects that can be removed while packets are enqueued in nfqueue. This can lead to issues when the module is removed or the timeout policy is changed. The vulnerability has been addressed by flushing enqueued packets when the template rule is removed. Affected product context requires defensive impact assessment and source-grounded technical framing.
Defensive priority
High
Recommended defensive actions
- Review and apply patches for the affected Linux kernel versions.
- Ensure that the Linux kernel is updated to a version that includes the fix for this vulnerability.
- Monitor for potential issues related to netfilter: xt_CT and template removal.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-03-25T11:16:39.707Z and was last modified on 2026-07-14T13:18:32.090Z. The NVD entry is currently Modified. This information is based on the provided source corpus. Further verification is recommended to ensure accuracy.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23391 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23391
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23391 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23391
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/19a230dec6bb8928e3f96387f9085cf2c79bcef9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/55445134d42b84cb0a272e42c98d233ca65eca83
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/63b8097cea1923fe82cd598068d0796da8c015ec
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/777d02efe3d630cca4c1b63962cec17c57711325
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cb549925875fa06dd155e49db4ac2c5044c30f9c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cc57506dd66555899560b9c0f24e813f034e12ec
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d2d0bae0c9a2a17b6990a2966f5cdce0813d6256
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.