Impact
The Linux kernel nf_tables subsystem contains a flaw where the chain blob allocation occurs after the ruleset is offloaded to the network interface card. This ordering creates a window in which the offloaded rules in hardware and the in‑kernel software rules diverge, potentially leading to packets being misclassified, dropped, or incorrectly forwarded, which can degrade firewall functionality or result in denial of service for legitimate traffic. The vulnerability stems from an improper sequencing of operations that leaves the system in an inconsistent state until the next update or reload resolves the mismatch.
Affected Systems
All Linux kernel distributions that have not incorporated the commit moving the hardware offload step after building the chain blob. Any host running an older kernel lacking this patch may be affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% shows that exploitation is considered unlikely at this time. Because the flaw is in kernel space, it requires local or privileged access to trigger the inconsistent state. The vulnerability is not listed in the CISA KEV catalog and no public exploit is known. The risk remains significant for systems still running vulnerable kernels, and mitigation is advisable.
OpenCVE Enrichment
Debian DLA
Debian DSA