7.8

CVE-2026-43084

netfilter: nfnetlink_queue: make hash table per queue

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_queue: make hash table per queue

Sharing a global hash table among all queues is tempting, but
it can cause crash:

BUG: KASAN: slab-use-after-free in nfqnl_recv_verdict+0x11ac/0x15e0 [nfnetlink_queue]
[..]
 nfqnl_recv_verdict+0x11ac/0x15e0 [nfnetlink_queue]
 nfnetlink_rcv_msg+0x46a/0x930
 kmem_cache_alloc_node_noprof+0x11e/0x450

struct nf_queue_entry is freed via kfree, but parallel cpu can still
encounter such an nf_queue_entry when walking the list.

Alternative fix is to free the nf_queue_entry via kfree_rcu() instead,
but as we have to alloc/free for each skb this will cause more mem
pressure.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 371de2bef6582a3f58049b3d18e190924af9c9a0
Version < 22730cb96093b5be0609063bbb1923dbecd61252
Status affected
Version 870e3e63da8e88daffe9d692a025c711658018a8
Version < 41e3652a178cb0eecd48e0e6e27fbb73a004046a
Status affected
Version 70e2e3ce4f6841e12ec1c104fc76c0e707398ec4
Version < 9e5ebef91120d2764aefe557c3a484b6288f341f
Status affected
Version e19079adcd26a25d7d3e586b1837493361fdf8b6
Version < 936206e3f6ff411581e615e930263d6f8b78df9d
Status affected
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 6.12.75
Version < 6.12.83
Status affected
Version 6.18.14
Version < 6.18.24
Status affected
Version 6.19.4
Version < 6.19.14
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.