CVE-2026-23458

Siemens ProductCERT Advisory SSA-019113

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() stores a conntrack pointer in cb->data for the netlink dump callback ctnetlink_exp_ct_dump_table(), but drops the conntrack reference immediately after netlink_dump_start(). When the dump spans multiple rounds, the second recvmsg() triggers the dump callback which dereferences the now-freed conntrack via nfct_help(ct), leading to a use-after-free on ct->ext. The bug is that the netlink_dump_control has no .start or .done callbacks to manage the conntrack reference across dump rounds. Other dump functions in the same file (e.g. ctnetlink_get_conntrack) properly use .start/.done callbacks for this purpose. Fix this by adding .start and .done callbacks that hold and release the conntrack reference for the duration of the dump, and move the nfct_help() call after the cb->args[0] early-return check in the dump callback to avoid dereferencing ct->ext unnecessarily. BUG: KASAN: slab-use-after-free in ctnetlink_exp_ct_dump_table+0x4f/0x2e0 Read of size 8 at addr ffff88810597ebf0 by task ctnetlink_poc/133 CPU: 1 UID: 0 PID: 133 Comm: ctnetlink_poc Not tainted 7.0.0-rc2+ #3 PREEMPTLAZY Call Trace: <TASK> ctnetlink_exp_ct_dump_table+0x4f/0x2e0 netlink_dump+0x333/0x880 netlink_recvmsg+0x3e2/0x4b0 ? aa_sk_perm+0x184/0x450 sock_recvmsg+0xde/0xf0 Allocated by task 133: kmem_cache_alloc_noprof+0x134/0x440 __nf_conntrack_alloc+0xa8/0x2b0 ctnetlink_create_conntrack+0xa1/0x900 ctnetlink_new_conntrack+0x3cf/0x7d0 nfnetlink_rcv_msg+0x48e/0x510 netlink_rcv_skb+0xc9/0x1f0 nfnetlink_rcv+0xdb/0x220 netlink_unicast+0x3ec/0x590 netlink_sendmsg+0x397/0x690 __sys_sendmsg+0xf4/0x180 Freed by task 0: slab_free_after_rcu_debug+0xad/0x1e0 rcu_core+0x5c3/0x9c0

Metrics

Severity
high
no public PoC known
7.8
Source: nvd-v3
3.0 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2021-09-26 00:00 UTC

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-24 22:10 UTC· nvd@nist.gov
    • Translation: Title: Linux, Description: En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: netfilter: ctnetlink: corrige uso después de liberación en ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() almacena un puntero conntrack en cb -> data para la devolución de llamada de volcado netlink ctnetlink_exp_ct_dump_table(), pero libera la referencia conntrack inmediatamente después de netlink_dump_start(). Cuando el volcado abarca múltiples rondas, el segundo recvmsg() activa la devolución de llamada de volcado que desreferencia el conntrack ahora liberado a través de nfct_help(ct), lo que lleva a un uso después de liberación en ct -> ext. El error es que netlink_dump_control no tiene devoluciones de llamada .start o .done para gestionar la referencia conntrack a través de las rondas de volcado. Otras funciones de volcado en el mismo archivo (p. ej., ctnetlink_get_conntrack) utilizan correctamente las devoluciones de llamada .start/.done para este propósito. Solucione esto añadiendo devoluciones de llamada .start y .done que retienen y liberan la referencia conntrack durante la duración del volcado, y mueva la llamada a nfct_help() después de la comprobación de retorno anticipado cb -> args[0] en la devolución de llamada de volcado para evitar desreferenciar ct -> ext innecesariamente. ERROR: KASAN: uso después de liberación de slab en ctnetlink_exp_ct_dump_table+0x4f/0x2e0 Lectura de tamaño 8 en la dirección ffff88810597ebf0 por la tarea ctnetlink_poc/133 CPU: 1 UID: 0 PID: 133 Comm: ctnetlink_poc No contaminado 7.0.0-rc2+ #3 PREEMPTLAZY Traza de Llamada: <TAREA> ctnetlink_exp_ct_dump_table+0x4f/0x2e0 netlink_dump+0x333/0x880 netlink_recvmsg+0x3e2/0x4b0 ? aa_sk_perm+0x184/0x450 sock_recvmsg+0xde/0xf0 Asignado por la tarea 133: kmem_cache_alloc_noprof+0x134/0x440 __nf_conntrack_alloc+0xa8/0x2b0 ctnetlink_create_conntrack+0xa1/0x900 ctnetlink_new_conntrack+0x3cf/0x7d0 nfnetlink_rcv_msg+0x48e/0x510 netlink_rcv_skb+0xc9/0x1f0 nfnetlink_rcv+0xdb/0x220 netlink_unicast+0x3ec/0x590 netlink_sendmsg+0x397/0x690 __sys_sendmsg+0xf4/0x180 Liberado por la tarea 0: slab_free_after_rcu_debug+0xad/0x1e0 rcu_core+0x5c3/0x9c0

Affected operating systems

  • linux

    amazon / amazon_linux

  • linux

    ubuntu / awsbionic

  • linux

    ubuntu / awsjammy

  • linux

    ubuntu / awsnoble

  • linux

    ubuntu / awsresolute

  • linux

    ubuntu / awsxenial

  • linux

    ubuntu / aws-6.8jammy

  • linux

    ubuntu / aws-hwexenial

  • linux

    ubuntu / azurejammy

  • linux

    ubuntu / azurenoble

  • linux

    ubuntu / azureresolute

  • linux

    ubuntu / azurexenial

  • linux

    ubuntu / azure-4.15bionic

  • linux

    suse / basesystem_module15

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux12.0

  • linux

    debian / debian_linux13.0

  • linux

    suse / development_tools_module15

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_aus8.4

  • linux

    redhat / enterprise_linux_aus8.6

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • arista

    cloudvision_agni2024.4.0 – 2025.2.2

  • arista

    cloudvision_portal2024.2.0 – 2026.1.0

  • arista

    velocloud_edge4.5.0 – 6.4.1

  • arista

    velocloud_gateway

  • arista

    velocloud_orchestrator

  • canonical

    ubuntu_linux

  • Citrix Systems

    Hypervisor8.2 CU1 LTSR

  • Citrix Systems

    XenServer8.4

  • Dell

    ECS3.8.1.0-3.8.1.7

  • Dell

    NetWorkerVirtual Edition

  • Dell

    NetWorkervProxy 19.13.0.3

  • Dell

    NetWorkervProxy 19.14

  • Dell

    PowerScale OneFS13.2.3

  • Dell

    PowerScale OneFSOneFS

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • gnupg

    libgcrypt1.11.0 – 1.11.3

  • gnupg

    libgcrypt1.12.0 – 1.12.2

  • gnupg

    libgcrypt1.8.8 – 1.10.4

  • Intel

    ProzessorCore Ultra 5

  • Intel

    ProzessorCore Ultra 7

  • Intel

    ProzessorCore Ultra 9

  • julia

    openssh_jll

  • netapp

    active_iq_unified_manager

  • netapp

    clustered_data_ontap

References & sources

Linked CVEs

Show 406 more CVEs
IDCVE-2026-23458
Siemens ProductCERT Advisory SSA-019113 — CVE-2026-23458 | NEOSEC Intel