7.8
CVE-2026-93288
- EPSS 0.13%
- Veröffentlicht 24.09.2026 16:02:12
- Zuletzt bearbeitet 03.10.2026 11:17:47
- Erkennungen
netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state sashiko reports: "nfnl_log_net_exit() calls nf_log_unset(), which clears the logger pointer without an RCU grace period. Immediately after, ops_free_list() frees the per-net state while concurrent packets might still be executing nf_log_packet() under rcu_read_lock()." Clear the pointer via .pre_exit to make sure rcu readers have completed before pernet storage is free'd. The change in nf_log_syslog.c is only done for consistency: it doesn't use pernet data.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
c83fa19603bdaeef17b815713dbbe3230c8a34ee
Version <
ba2e246aa294f9acd86194ea87fb6834ed0a37ac
Status
affected
Version
c83fa19603bdaeef17b815713dbbe3230c8a34ee
Version <
5570d6c8b320dbcc602617ee08c27ce752fed65a
Status
affected
Version
c83fa19603bdaeef17b815713dbbe3230c8a34ee
Version <
3b9aa62d78ce80de47af2db472ff452398755213
Status
affected
Version
c83fa19603bdaeef17b815713dbbe3230c8a34ee
Version <
f4461654374576e9d5d0245fd534c46ad8509051
Status
affected
Version
c83fa19603bdaeef17b815713dbbe3230c8a34ee
Version <
dc20050b6b12ca58066715d088e1a537535d938d
Status
affected
Version
c83fa19603bdaeef17b815713dbbe3230c8a34ee
Version <
33d1469b0124cc0baaea7a2032123b77a81e0940
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.12
Status
affected
Version
0
Version <
4.12
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.02 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/f4461654374576e9d5d0245fd534c46ad8509051
https://git.kernel.org/stable/c/dc20050b6b12ca58066715d088e1a537535d938d
https://git.kernel.org/stable/c/33d1469b0124cc0baaea7a2032123b77a81e0940
https://git.kernel.org/stable/c/3b9aa62d78ce80de47af2db472ff452398755213
https://git.kernel.org/stable/c/5570d6c8b320dbcc602617ee08c27ce752fed65a
https://git.kernel.org/stable/c/ba2e246aa294f9acd86194ea87fb6834ed0a37ac