A use-after-free flaw in the Linux kernel traffic control act_ct path, tracked as CVE-2026-23270, was disclosed after maintainers found that incorrect binding to non-ingress egress qdiscs could leave the defragmentation engine holding an skb that had already been treated as consumed. The bug affects the net/sched subsystem and can let a local user with the required privileges trigger a kernel crash, causing denial of service, and in some cases potentially achieve privilege escalation. Upstream kernel maintainers fixed the issue by restricting act_ct so it can bind only to clsact/ingress qdiscs and shared blocks, while still allowing egress attachment only through clsact.
The Linux kernel CVE team said the flaw was introduced in kernel branches starting with 6.8 and selected stable backports, with fixes released in 6.12.77, 6.18.18, 6.19.8, and 7.0-rc3. Red Hat rated the issue Moderate and noted that exploitation depends on a specific misconfiguration, but still shipped fixes across multiple RHEL 8, 9, and 10 kernel packages through security errata, including RHSA-2026:13566 for RHEL 10. That advisory bundled CVE-2026-23270 with other kernel fixes and instructed customers to install updated kernel packages and reboot affected systems after applying the update.

Get the actors, campaigns, and ATT&CK mapping behind it.
20 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-04, Red Hat published RHSA-2026:13566, an Important kernel security update for Red Hat Enterprise Linux 10 that includes a fix for CVE-2026-23270.
On 2026-05-04, Red Hat released RHSA-2026:13565 to fix CVE-2026-23270 in Red Hat Enterprise Linux 9 kernel packages.
Red Hat published its CVE record for CVE-2026-23270 on 2026-03-18, classifying the Linux kernel flaw as Moderate severity and linking it to Bugzilla 2448745.
On 2026-03-18, the Linux kernel CVE team published the CVE-2026-23270 announcement describing a use-after-free in net/sched act_ct and the remediation restricting act_ct binding to clsact/ingress qdiscs and shared blocks.
On 2026-07-06, Red Hat released RHSA-2026:35863 to fix CVE-2026-23270 for Red Hat Enterprise Linux 8.8 Telecommunications Update Service and 8.8 Update Services for SAP Solutions.
Red Hat last modified its CVE-2026-23270 entry on 2026-06-30, updating the vendor record for the Linux kernel vulnerability.
On 2026-06-08, Red Hat released RHSA-2026:24343 to fix CVE-2026-23270 in Red Hat Enterprise Linux 10.0 Extended Update Support kernel packages.
On 2026-06-03, Red Hat released RHSA-2026:22940 to fix CVE-2026-23270 in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions kernel packages.
On 2026-05-28, Red Hat released RHSA-2026:21706 for RHEL 8 kernel packages and RHSA-2026:21745 for RHEL 8 kernel-rt packages to address CVE-2026-23270.
On 2026-05-20, Red Hat issued RHSA-2026:19569 with additional fixes for CVE-2026-23270 in Red Hat Enterprise Linux 10 kernel packages.
On 2026-05-20, Red Hat issued RHSA-2026:19568 with additional fixes for CVE-2026-23270 in Red Hat Enterprise Linux 9 kernel packages.
The vulnerability was fixed in Linux kernel 7.0-rc3 by commit 11cb63b0d1a0685e0831ae3c77223e002ef18189.
The vulnerability was fixed in Linux kernel 6.19.8 by commit 9deda0fcda5c1f388c5e279541850b71a2ccfcf4.
The vulnerability was fixed in Linux kernel 6.18.18 by commit 380ad8b7c65ea7aa10ef2258297079ed5ac1f5b6.
The vulnerability was fixed in Linux kernel 6.12.77 by commit 524ce8b4ea8f64900b6c52b6a28df74f6bc0801e.
The issue was also introduced into the 6.7 stable branch in version 6.7.2 by commit f5346df0591d10bc948761ca854b1fae6d2ef441.
The vulnerable change was also introduced into the 6.6 stable branch in version 6.6.14 by commit 73f7da5fd124f2cda9161e2e46114915e6e82e97.
The issue was also introduced into the 6.1 stable branch in version 6.1.75 by commit 0b5b831122fc3789fff75be433ba3e4dd7b779d4.
The vulnerable change was also introduced into the 5.15 stable branch in version 5.15.148 by commit 172ba7d46c202e679f3ccb10264c67416aaeb1c4.
CVE-2026-23270 was introduced into the Linux kernel 6.8 branch by commit 3f14b377d01d8357eba032b4cabc8c1149b458b6, creating the act_ct binding flaw in net/sched.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.