CVE-2026-23333
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23333 is a vulnerability in the Linux kernel's netfilter nft_set_rbtree component related to improper validation of open interval overlaps in firewall rulesets. It was published on March 25, 2026, and subsequently rejected/withdrawn by its CVE Numbering Authority (CNA) on April 13, 2026 (Kernel CVE Announce). The affected component is the Linux kernel netfilter subsystem. Prior to rejection, it carried a CVSS v3.1 base score of 5.5 (Medium) (Red Hat).

Technical details

The issue was classified under CWE-1288 (Improper Validation of Consistency within Input) and resided in the nft_set_rbtree interval validation logic (Red Hat). Open intervals — those lacking an end element — at the end of a netfilter set could not be properly checked for overlaps with existing intervals, allowing duplicate or overlapping interval insertion. The upstream fix (commit 648946966a08e4cb1a71619e3d1b12bd7642de7b) added a new flag field to struct nft_set_elem to mark the last element in add/delete commands, enabling proper overlap detection (Red Hat Bugzilla). Exploitation required CAP_NET_ADMIN privileges, limiting the attack surface to local privileged users.

Impact

Prior to the CVE's rejection, the described impact was that attackers holding CAP_NET_ADMIN capabilities could insert duplicate or overlapping intervals into netfilter rulesets, causing inconsistent packet filtering behavior (Red Hat). This could result in firewall policy bypass — allowing unauthorized network traffic or dropping legitimate traffic — without affecting confidentiality or integrity of data directly. The CVSS assessment reflected a High availability impact with no confidentiality or integrity impact, scoped to the local system.

Mitigation and workarounds

The upstream fix is available in the Linux kernel via commit 648946966a08e4cb1a71619e3d1b12bd7642de7b (Red Hat Bugzilla). As a precautionary measure, CAP_NET_ADMIN capabilities should be restricted to trusted administrators only. Note that this CVE has been officially rejected/withdrawn by its CNA, so no formal vendor patch advisory is expected; administrators should apply the upstream kernel fix as part of routine kernel updates.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management