7.8

CVE-2026-74565

netfilter: nf_tables: make nft_object rhltable per table

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: make nft_object rhltable per table

The nft_object rhltable is global, this allows for accessing objects
that are being dismangled from lookup path by other existing netns.
Given the nft_obj_destroy() releases the object inmediately, this might
lead to use-after-free of these objects that are being released.
Make the existing rhltable per table to address this issue to deal with
with the nft_rcv_nl_event() path too.

Update nft_obj_lookup() to take the table as non-const, otherwise,
compiler complains when passing the objname_ht to rhltable_lookup().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 4d44175aa5bb5f68772b1eb0306554812294ca52
Version < 1948e4f85b855618b5b9a27265f98d816f4cb7cb
Status affected
Version 4d44175aa5bb5f68772b1eb0306554812294ca52
Version < 63ba12b664a2cd3220ed43e22c717715f4cc2ae8
Status affected
Version 4d44175aa5bb5f68772b1eb0306554812294ca52
Version < 7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af
Status affected
Version 4d44175aa5bb5f68772b1eb0306554812294ca52
Version < f4f699790590bd0896c48a71e9232a65198f92f0
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.1
Status affected
Version 0
Version < 5.1
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.019
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1948e4f85b855618b5b9a27265f98d816f4cb7cb
https://git.kernel.org/stable/c/63ba12b664a2cd3220ed43e22c717715f4cc2ae8
https://git.kernel.org/stable/c/7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af
https://git.kernel.org/stable/c/f4f699790590bd0896c48a71e9232a65198f92f0