PT-2026-27698 · Linux · Linux Kernel

CVE-2026-23333

·

Publicado

2026-01-01

·

Atualizado

2026-08-21

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the netfilter module related to the validation of open intervals within nft set rbtree. Specifically, the issue arises from the lack of a defined end element for open intervals, making overlap validation challenging. The vulnerability can occur when adding or deleting intervals, potentially leading to incorrect behavior. The patch introduces a flag within the nft set elem structure to identify the last element in an add/delete command, enabling more accurate overlap checks. The issue can manifest when adding intervals that overlap with existing start elements, or when deleting open intervals and subsequently adding new elements.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Resource Exhaustion

Improper Resource Release

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-12471
CVE-2026-23333

Produtos afetados

Linux Kernel