
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23333 is a vulnerability in the Linux kernel's netfilter nft_set_rbtree component related to improper validation of open interval overlaps in firewall rulesets. It was published on March 25, 2026, and subsequently rejected/withdrawn by its CVE Numbering Authority (CNA) on April 13, 2026 (Kernel CVE Announce). The affected component is the Linux kernel netfilter subsystem. Prior to rejection, it carried a CVSS v3.1 base score of 5.5 (Medium) (Red Hat).
The issue was classified under CWE-1288 (Improper Validation of Consistency within Input) and resided in the nft_set_rbtree interval validation logic (Red Hat). Open intervals — those lacking an end element — at the end of a netfilter set could not be properly checked for overlaps with existing intervals, allowing duplicate or overlapping interval insertion. The upstream fix (commit 648946966a08e4cb1a71619e3d1b12bd7642de7b) added a new flag field to struct nft_set_elem to mark the last element in add/delete commands, enabling proper overlap detection (Red Hat Bugzilla). Exploitation required CAP_NET_ADMIN privileges, limiting the attack surface to local privileged users.
Prior to the CVE's rejection, the described impact was that attackers holding CAP_NET_ADMIN capabilities could insert duplicate or overlapping intervals into netfilter rulesets, causing inconsistent packet filtering behavior (Red Hat). This could result in firewall policy bypass — allowing unauthorized network traffic or dropping legitimate traffic — without affecting confidentiality or integrity of data directly. The CVSS assessment reflected a High availability impact with no confidentiality or integrity impact, scoped to the local system.
The upstream fix is available in the Linux kernel via commit 648946966a08e4cb1a71619e3d1b12bd7642de7b (Red Hat Bugzilla). As a precautionary measure, CAP_NET_ADMIN capabilities should be restricted to trusted administrators only. Note that this CVE has been officially rejected/withdrawn by its CNA, so no formal vendor patch advisory is expected; administrators should apply the upstream kernel fix as part of routine kernel updates.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."