---
cve: "CVE-2026-23231"
severity: "HIGH"
cvss: 7.8
epss: "79%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-03-04 13:15:58"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T10:39:19+02:00"
---

# CVE-2026-23231

> 7.8 HIGH

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: fix use-after-free in nf_tables_addchain()

nf_tables_addchain() publishes the chain to table->chains via
list_add_tail_rcu() (in nft_chain_add()) before registering hooks.
If nf_tables_register_hook() then fails, the error path calls
nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy()
with no RCU grace period in between.

This creates two use-after-free conditions:

 1) Control-plane: nf_tables_dump_chains() traverses table->chains
    under rcu_read_lock(). A concurrent dump can still be walking
    the chain when the error path frees it.

 2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly
    installs the IPv4 hook before IPv6 registration fails.  Packets
    entering nft_do_chain() via the transient IPv4 hook can still be
    dereferencing chain->blob_gen_X when the error path frees the
    chain.

Add synchronize_rcu() between nft_chain_del() and the chain destroy
so that all RCU readers -- both dump threads and in-flight packet
evaluation -- have finished before the chain is freed.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Exploit-Evidenz

- [EDB-52549 — Linux nf_tables 6.19.3 - Local Privilege Escalation](https://www.exploit-db.com/exploits/52549)

## Patch verfügbar (OSV)

- Kernel ≥ 6.1.165
- Kernel ≥ 6.6.128
- Kernel ≥ 6.12.75
- Kernel ≥ 6.18.14
- Kernel ≥ 6.19.4

## Referenzen

- <https://git.kernel.org/stable/c/2a6586ecfa4ce1413daaafee250d2590e05f1a33>
- <https://git.kernel.org/stable/c/7017745068a9068904e1e7a1b170a5785647cc81>
- <https://git.kernel.org/stable/c/f3fe58ce37926a10115ede527d59b91bcc05400a>
- <https://git.kernel.org/stable/c/dbd0af8083dd201f07c49110b2ee93710abdff28>
- <https://git.kernel.org/stable/c/2f9a4ffeb763aec822f8ff3d1e82202d27d46d4b>
- <https://git.kernel.org/stable/c/71e99ee20fc3f662555118cf1159443250647533>
- <https://cert-portal.siemens.com/productcert/html/ssa-019113.html>
- <https://cert-portal.siemens.com/productcert/html/ssa-082556.html>
- <https://cert-portal.siemens.com/productcert/html/ssa-253495.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-23231) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
