CVE-2026-23391
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/03/2026
Last modified:
25/03/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: xt_CT: drop pending enqueued packets on template removal<br />
<br />
Templates refer to objects that can go away while packets are sitting in<br />
nfqueue refer to:<br />
<br />
- helper, this can be an issue on module removal.<br />
- timeout policy, nfnetlink_cttimeout might remove it.<br />
<br />
The use of templates with zone and event cache filter are safe, since<br />
this just copies values.<br />
<br />
Flush these enqueued packets in case the template rule gets removed.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/19a230dec6bb8928e3f96387f9085cf2c79bcef9
- https://git.kernel.org/stable/c/63b8097cea1923fe82cd598068d0796da8c015ec
- https://git.kernel.org/stable/c/777d02efe3d630cca4c1b63962cec17c57711325
- https://git.kernel.org/stable/c/cb549925875fa06dd155e49db4ac2c5044c30f9c
- https://git.kernel.org/stable/c/d2d0bae0c9a2a17b6990a2966f5cdce0813d6256
- https://git.kernel.org/stable/c/f62a218a946b19bb59abdd5361da85fa4606b96b



