
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23333 is a vulnerability in the Linux kernel's netfilter nft_set_rbtree component related to improper validation of open interval overlaps in firewall rulesets. It was published on March 25, 2026, and subsequently rejected/withdrawn by its CVE Numbering Authority (CNA) on April 13, 2026 (Kernel CVE Announce). The affected component is the Linux kernel netfilter subsystem. Prior to rejection, it carried a CVSS v3.1 base score of 5.5 (Medium) (Red Hat).
The issue was classified under CWE-1288 (Improper Validation of Consistency within Input) and resided in the nft_set_rbtree interval validation logic (Red Hat). Open intervals — those lacking an end element — at the end of a netfilter set could not be properly checked for overlaps with existing intervals, allowing duplicate or overlapping interval insertion. The upstream fix (commit 648946966a08e4cb1a71619e3d1b12bd7642de7b) added a new flag field to struct nft_set_elem to mark the last element in add/delete commands, enabling proper overlap detection (Red Hat Bugzilla). Exploitation required CAP_NET_ADMIN privileges, limiting the attack surface to local privileged users.
Prior to the CVE's rejection, the described impact was that attackers holding CAP_NET_ADMIN capabilities could insert duplicate or overlapping intervals into netfilter rulesets, causing inconsistent packet filtering behavior (Red Hat). This could result in firewall policy bypass — allowing unauthorized network traffic or dropping legitimate traffic — without affecting confidentiality or integrity of data directly. The CVSS assessment reflected a High availability impact with no confidentiality or integrity impact, scoped to the local system.
There is no evidence of a public proof-of-concept or in-the-wild exploitation for this CVE (Red Hat). The EPSS score is extremely low at 0.000180, indicating a negligible probability of exploitation. The CVE has since been rejected by its CNA, meaning it is no longer considered a valid, distinct vulnerability entry (Kernel CVE Announce). It does not appear in the CISA Known Exploited Vulnerabilities catalog.
The upstream fix is available in the Linux kernel via commit 648946966a08e4cb1a71619e3d1b12bd7642de7b (Red Hat Bugzilla). As a precautionary measure, CAP_NET_ADMIN capabilities should be restricted to trusted administrators only. Note that this CVE has been officially rejected/withdrawn by its CNA, so no formal vendor patch advisory is expected; administrators should apply the upstream kernel fix as part of routine kernel updates.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."