{"schema_version":"1.7.5","id":"CVE-2026-23274","published":"2026-03-20T08:08:54.918Z","modified":"2026-07-16T03:30:51.483609963Z","related":["SUSE-SU-2026:1342-1","SUSE-SU-2026:1557-1","SUSE-SU-2026:1563-1","SUSE-SU-2026:1573-1","SUSE-SU-2026:1574-1","SUSE-SU-2026:1575-1","SUSE-SU-2026:1606-1","SUSE-SU-2026:1643-1","SUSE-SU-2026:1661-1","SUSE-SU-2026:21114-1","SUSE-SU-2026:21123-1","SUSE-SU-2026:21230-1","SUSE-SU-2026:21237-1","SUSE-SU-2026:21255-1","SUSE-SU-2026:2131-1","SUSE-SU-2026:2134-1","SUSE-SU-2026:21352-1","SUSE-SU-2026:21361-1","SUSE-SU-2026:2141-1","SUSE-SU-2026:2149-1","SUSE-SU-2026:2158-1","SUSE-SU-2026:2159-1","SUSE-SU-2026:2172-1","SUSE-SU-2026:2176-1","SUSE-SU-2026:2181-1","SUSE-SU-2026:21886-1","SUSE-SU-2026:21887-1","SUSE-SU-2026:21888-1","SUSE-SU-2026:21889-1","SUSE-SU-2026:2189-1","SUSE-SU-2026:21890-1","SUSE-SU-2026:21891-1","SUSE-SU-2026:21892-1","SUSE-SU-2026:21893-1","SUSE-SU-2026:21894-1","SUSE-SU-2026:21896-1","SUSE-SU-2026:21900-1","SUSE-SU-2026:21901-1","SUSE-SU-2026:21902-1","SUSE-SU-2026:21903-1","SUSE-SU-2026:21904-1","SUSE-SU-2026:21905-1","SUSE-SU-2026:21906-1","SUSE-SU-2026:21907-1","SUSE-SU-2026:21908-1","SUSE-SU-2026:21910-1","SUSE-SU-2026:21921-1","SUSE-SU-2026:21922-1","SUSE-SU-2026:21923-1","SUSE-SU-2026:21924-1","SUSE-SU-2026:21925-1","SUSE-SU-2026:21926-1","SUSE-SU-2026:21927-1","SUSE-SU-2026:21928-1","SUSE-SU-2026:21929-1","SUSE-SU-2026:21930-1","SUSE-SU-2026:21932-1","SUSE-SU-2026:21933-1","SUSE-SU-2026:21934-1","SUSE-SU-2026:21935-1","SUSE-SU-2026:21936-1","SUSE-SU-2026:21937-1","SUSE-SU-2026:21938-1","SUSE-SU-2026:21939-1","SUSE-SU-2026:21940-1","SUSE-SU-2026:21942-1","SUSE-SU-2026:21956-1","SUSE-SU-2026:21958-1","SUSE-SU-2026:21959-1","SUSE-SU-2026:21960-1","SUSE-SU-2026:21962-1","SUSE-SU-2026:21963-1","SUSE-SU-2026:21969-1","SUSE-SU-2026:21970-1","SUSE-SU-2026:21972-1","SUSE-SU-2026:21974-1","SUSE-SU-2026:21979-1","SUSE-SU-2026:21982-1","SUSE-SU-2026:21983-1","SUSE-SU-2026:2199-1","SUSE-SU-2026:22030-1","SUSE-SU-2026:22031-1","SUSE-SU-2026:22033-1","SUSE-SU-2026:22035-1","SUSE-SU-2026:22038-1","SUSE-SU-2026:22039-1","SUSE-SU-2026:22040-1","SUSE-SU-2026:22042-1","openSUSE-SU-2026:20572-1"],"summary":"netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels\n\nIDLETIMER revision 0 rules reuse existing timers by label and always call\nmod_timer() on timer->timer.\n\nIf the label was created first by revision 1 with XT_IDLETIMER_ALARM,\nthe object uses alarm timer semantics and timer->timer is never initialized.\nReusing that object from revision 0 causes mod_timer() on an uninitialized\ntimer_list, triggering debugobjects warnings and possible panic when\npanic_on_warn=1.\n\nFix this by rejecting revision 0 rule insertion when an existing timer with\nthe same label is of ALARM type.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"68983a354a655c35d3fb204489d383a2a051fda7"},{"fixed":"32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44"},{"fixed":"144f88054ba0180467356f40895bd660b5dceeec"},{"fixed":"28c7cfaf0c0ab17cbd7754092116fd1af45271f9"},{"fixed":"54080355999381fed4a26129579a5765bab87491"},{"fixed":"5e7ece24c5cb75a60402aad4d803c7898ea40aa9"},{"fixed":"f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1"},{"fixed":"f228b9ae2a7e84d1153616d8e71c4236cb1f1309"},{"fixed":"329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23274.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.7.0"},{"fixed":"5.10.253"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.203"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.167"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.130"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.78"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.19"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23274.json"}}],"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html"},{"type":"WEB","url":"https://git.kernel.org/stable/c/144f88054ba0180467356f40895bd660b5dceeec"},{"type":"WEB","url":"https://git.kernel.org/stable/c/28c7cfaf0c0ab17cbd7754092116fd1af45271f9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/329f0b9b48ee6ab59d1ab72fef55fe8c6463a6cf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/32e937dc6e97f5ed3cdfe3fc0b2b19a05e23fa44"},{"type":"WEB","url":"https://git.kernel.org/stable/c/54080355999381fed4a26129579a5765bab87491"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5e7ece24c5cb75a60402aad4d803c7898ea40aa9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f228b9ae2a7e84d1153616d8e71c4236cb1f1309"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f5ef97c13165542480a6ffdbe6f09f40bbb7cbf1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23274.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23274"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23274.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}