CVE-2026-23397 | Linux Kernel up to 7.0-rc4 nfnetlink_osf nfnetlink_osf.c nfnl_osf_add_callback out-of-bounds (WID-SEC-2026-0879)
A vulnerability was found in Linux Kernel up to 7.0-rc4. It has been rated as critical. This issue affects the function nfnl_osf_add_callback of the file net/netfilter/nfnetlink_osf.c of the component nfnetlink_osf. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-23397. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.