CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
In the Linux kernel, the following vulnerability has been resolved:
Other sources
netfilter: xtIDLETIMER: reject rev0 reuse of ALARM timer labels
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1Fixed in 7.0.12-2 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.174-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23274?
CVE-2026-23274 is considered a medium severity vulnerability affecting the Linux kernel netfilter xt_IDLETIMER.
How do I fix CVE-2026-23274?
To fix CVE-2026-23274, upgrade your Linux kernel to the latest stable version that includes the patch resolving this issue.
What components are impacted by CVE-2026-23274?
CVE-2026-23274 specifically impacts the Linux netfilter xt_IDLETIMER module.
What type of vulnerability is CVE-2026-23274?
CVE-2026-23274 is a vulnerability related to timer label reuse within the netfilter module.
Is CVE-2026-23274 actively exploited?
As of now, there have been no public reports indicating that CVE-2026-23274 is actively exploited in the wild.