HomeDefectsLIN1025-8838
Fixed

LIN1025-8838 : Security Advisory - linux - CVE-2026-23412

Created: Apr 3, 2026    Updated: Apr 8, 2026
Resolved Date: Apr 6, 2026
Found In Version: 10.25.33.2
Fix Version: 10.25.33.8
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  netfilter: bpf: defer hook memory release until rcu readers are done  Yiming Qian reports UaF when concurrent process is dumping hooks via nfnetlink_hooks:  BUG: KASAN: slab-use-after-free in nfnl_hook_dump_one.isra.0+0xe71/0x10f0 Read of size 8 at addr ffff888003edbf88 by task poc/79 Call Trace:  <TASK>  nfnl_hook_dump_one.isra.0+0xe71/0x10f0  netlink_dump+0x554/0x12b0  nfnl_hook_get+0x176/0x230  [..]  Defer release until after concurrent readers have completed.