Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-23412— netfilter: bpf: defer hook memory release until rcu readers are done

CVSS 7.8 · High EPSS 0.01% · P3
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-23412

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: bpf: defer hook memory release until rcu readers are done
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qian reports UaF when concurrent process is dumping hooks via nfnetlink_hooks: BUG: KASAN: slab-use-after-free in nfnl_hook_dump_one.isra.0+0xe71/0x10f0 Read of size 8 at addr ffff888003edbf88 by task poc/79 Call Trace: <TASK> nfnl_hook_dump_one.isra.0+0xe71/0x10f0 netlink_dump+0x554/0x12b0 nfnl_hook_get+0x176/0x230 [..] Defer release until after concurrent readers have completed.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于netfilter bpf延迟释放内存,可能导致释放后重用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 84601d6ee68ae820dec97450934797046d62db4b ~ d016c216bc75c45128160593a77b864a04dbe7c0 -
LinuxLinux 6.4 -

II. Public POCs for CVE-2026-23412

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-23412

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-04-02 · 6 CVEs total

CVE-2026-234157.8 HIGHfutex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy()
CVE-2026-234137.8 HIGHclsact: Fix use-after-free in init/destroy rollback asymmetry
CVE-2026-234147.5 HIGHtls: Purge async_hold in tls_decrypt_async_wait()
CVE-2026-23417bpf: Fix constant blinding for PROBE_MEM32 stores
CVE-2026-23416mm/mseal: update VMA end correctly on merge

IV. Related Vulnerabilities

V. Comments for CVE-2026-23412

No comments yet


Leave a comment