CVE-2026-23270: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks As Paolo said earlier [1]: "Since the blamed commit below, classify can return TC_ACT_CONSUMED while the current skb being held by the defragmentation engine. As reported by GangMin Kim, if such packet is that may cause a UaF when the defrag engine later on tries to tuch again such packet." act_ct was never meant to be used in the egress path, however some users are attaching it to egress today [2]. Attempting to reach a middle ground, we noticed that, while most qdiscs are not handling TC_ACT_CONSUMED, clsact/ingress qdiscs are. With that in mind, we address the issue by only allowing act_ct to bind to clsact/ingress qdiscs and shared blocks. That way it's still possible to attach act_ct to egress (albeit only with clsact). [1] https://lore.kernel.org/netdev/674b8cbfc385c6f37fb29a1de08d8fe5c2b0fbee.1771321118.git.pabeni@redhat.com/ [2] https://lore.kernel.org/netdev/cc6bfb4a-4a2b-42d8-b9ce-7ef6644fb22b@ovn.org/

Affected products

  • Linux Linux Kernel: from 5.15.148, before 5.15.203 (fixed in 5.15.203); from 6.1.75, before 6.1.167 (fixed in 6.1.167); from 6.6.14, before 6.6.130 (fixed in 6.6.130); from 6.7.2, before 6.8 (fixed in 6.8); from 6.8, before 6.12.77 (fixed in 6.12.77); from 6.13, before 6.18.18 (fixed in 6.18.18); …

Published 2026-03-18. Last modified 2026-07-14.