CVE-2026-23010 is a use-after-free vulnerability in the Linux kernel's inet6_addr_del() function. Incorrect operation ordering calls ipv6_del_addr() for mngtmpaddr handling before reading ifp->flags for temporary IPv6 addresses, allowing an inet6_ifaddr object to be accessed after it has been freed. A syzbot reproducer detected a four-byte read from freed slab memory through the IPv6 address-deletion ioctl path. The flaw may cause denial of service; privilege escalation is a possible but unconfirmed consequence.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal standalone Python proof-of-concept for CVE-2026-23010, illustrating a replay vulnerability in a CCSDS-like satellite telecommand handling workflow. The repository contains three files: an MIT LICENSE, a README describing the issue and usage, and a single code file, satellite_sim.py. The Python code defines a Satellite class with a receive_tc(cmd_id, seq_num) method that ignores the seq_num parameter and directly executes the command, modeling the core flaw: lack of freshness/sequence validation. The demonstration invokes the same telecommand twice with the same sequence number, showing duplicate execution of ORBIT_CORRECTION. There is no real packet parsing, networking stack, radio interface, or remote endpoint interaction; this is a conceptual exploit simulation rather than an operational exploit against a live target. Main exploit capability: demonstrating that intercepted telecommands can be replayed unchanged and still be accepted. No shell, code execution, persistence, or post-exploitation behavior is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A use-after-free vulnerability in the Linux kernel's IPv6 address deletion code. An incorrectly ordered ipv6_del_addr() call frees an inet6_ifaddr object before its flags are read. The fix moves the deletion call after the read. The reference assigns a CVSS v3 base score of 7.8, indicating local exploitation requiring low privileges and potentially high confidentiality, integrity, and availability impact.
A use-after-free vulnerability in the Linux kernel's IPv6 address-deletion logic. An incorrectly ordered ipv6_del_addr() call frees an address object before its flags are read. The advisory assigns CVSS v3 severity 7.8, with local access and low privileges required and potential high confidentiality, integrity, and availability impacts. Update Echo's linux package and related packages to version 6.1.162-1 or later.
A high-severity local use-after-free vulnerability in the Linux kernel IPv6 address-configuration code, specifically inet6_addr_del(). It can occur when temporary IPv6 addresses are deleted; a KASAN report shows a read from a freed inet6_ifaddr object. Google COS systems using the affected csql-kernel-6_1 package should update to version 18244.582.11 or later.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.