Bug 2541175 (CVE-2026-97998) - CVE-2026-97998 kernel: netfilter: nfnetlink_log: cope with concurrent instance destruction
Summary: CVE-2026-97998 kernel: netfilter: nfnetlink_log: cope with concurrent instanc...
Keywords:
Status: NEW
Alias: CVE-2026-97998
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 10:54 UTC by OSIDB Bzimport
Modified: 2026-09-30 10:17 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 10:54:50 UTC
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_log: cope with concurrent instance destruction

Instances are refcounted. However, only memory release happens on the
1 -> 0 transition; the unlink from hashes can occur with any refcount.

Uncooperative userspace can force a situation where a queue is pending
for destruction from netlink event while a different socket with same
portid processes an UNBIND request.

With right timing, this will unhash the instance again:

Oops: general protection fault, [..]
Call Trace:
 <TASK>
 nfulnl_recv_config+0x31a/0xd50
 nfnetlink_rcv_msg+0x7c2/0xeb0


Note You need to log in before you can comment on or make changes to this bug.