Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_counter: serialize reset with spinlock

Add a global static spinlock to serialize counter fetch+reset
operations, preventing concurrent dump-and-reset from underrunning
values.

The lock is taken before fetching the total so that two parallel
resets cannot both read the same counter values and then both
subtract them.

A global lock is used for simplicity since resets are infrequent.
If this becomes a bottleneck, it can be replaced with a per-net
lock later.
Published: 2026-05-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a race condition in the netfilter nft_counter subsystem where simultaneous dump and reset operations are performed without proper synchronization. If two resets occur concurrently, they can each read the same counter totals and subtract them twice, resulting in counters that are lower than the actual values. Based on the description, it is inferred that an attacker with local or kernel-privileged access could trigger this race, causing inaccurate accounting of network traffic, potentially misleading administrators about traffic volumes and patterns.

Affected Systems

All Linux kernel installations that include the netfilter nft_counter code path are affected. Any distribution or release built before the patch that allows concurrent counter operations is vulnerable. The fix injects a global static spinlock to serialize fetch-and-reset calls, preventing the race. The patch has been applied to the kernel, but affected systems must upgrade to a version containing the commit.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% shows that the likelihood of exploitation is very low. Based on the description, it is inferred that this is a kernel-level race condition that requires local or kernel-privileged access and does not provide a pathway to remote code execution or privilege escalation. The vulnerability is not listed in CISA’s KEV catalog. The primary impact is on the accuracy of firewall counters rather than on system availability.

Generated by OpenCVE AI on August 14, 2026 at 02:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the nft_counter reset serialization patch
  • Reboot or otherwise reload networking services to ensure the updated kernel and spinlock protection are active
  • If an immediate upgrade is not possible, limit or disable nft_counter rules that trigger concurrent counter operations until the patch is applied
  • Check the vendor’s security advisories for updates or additional guidance

Generated by OpenCVE AI on August 14, 2026 at 02:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4745-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6415-1 linux security update
History

Mon, 03 Aug 2026 10:15:00 +0000


Thu, 28 May 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 28 May 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-820
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Wed, 27 May 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_counter: serialize reset with spinlock Add a global static spinlock to serialize counter fetch+reset operations, preventing concurrent dump-and-reset from underrunning values. The lock is taken before fetching the total so that two parallel resets cannot both read the same counter values and then both subtract them. A global lock is used for simplicity since resets are infrequent. If this becomes a bottleneck, it can be replaced with a per-net lock later.
Title netfilter: nft_counter: serialize reset with spinlock
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-03T09:32:30.454Z

Reserved: 2026-05-13T15:03:33.083Z

Link: CVE-2026-45897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-05-27T14:17:03.977

Modified: 2026-08-03T10:16:28.753

Link: CVE-2026-45897

cve-icon Redhat

Severity : Low

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-45897 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T02:15:03Z

Weaknesses