Impact
In the Linux kernel’s nf_tables subsystem, inserting a set element without providing an override expression causes the system to clone the existing set expressions twice—once to duplicate the template and again when creating the new element. This double cloning inflates reference counters within the kernel module and can trigger a module refcount imbalance warning. The change also fixed a related bug in the connlimit expression that previously produced such warnings during resorting on default set expressions.
Affected Systems
All Linux kernel releases that contain the nf_tables framework may be affected; no specific kernel version is identified in the data.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely require a local or privileged process capable of manipulating nf_tables set entries. The available data does not indicate a known remote exploit or high likelihood of successful exploitation.
OpenCVE Enrichment