Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: move hardware offload step after building the chain blob

Allocate the chain blob before the ruleset offload to reduce chances of
entering an inconsistent state where the offloaded ruleset in the nic
and the software ruleset differ.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Inconsistent firewall rule state potentially causing packet filtering failures or denial of service
Action: Apply Kernel Update
AI Analysis

Impact

The Linux kernel nf_tables subsystem contains a flaw where the chain blob allocation occurs after the ruleset is offloaded to the network interface card. This ordering creates a window in which the offloaded rules in hardware and the in‑kernel software rules diverge, potentially leading to packets being misclassified, dropped, or incorrectly forwarded, which can degrade firewall functionality or result in denial of service for legitimate traffic. The vulnerability stems from an improper sequencing of operations that leaves the system in an inconsistent state until the next update or reload resolves the mismatch.

Affected Systems

All Linux kernel distributions that have not incorporated the commit moving the hardware offload step after building the chain blob. Any host running an older kernel lacking this patch may be affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% shows that exploitation is considered unlikely at this time. Because the flaw is in kernel space, it requires local or privileged access to trigger the inconsistent state. The vulnerability is not listed in the CISA KEV catalog and no public exploit is known. The risk remains significant for systems still running vulnerable kernels, and mitigation is advisable.

Generated by OpenCVE AI on September 20, 2026 at 04:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the change to allocate the chain blob before the hardware offload step
  • Restart networking services or reboot the host to ensure the new kernel loads and nf_tables reinitializes
  • Validate that the NIC offloaded rule set matches the kernel’s software rule set using nf_tables tools or netlink, and monitor kernel logs for offload synchronization errors

Generated by OpenCVE AI on September 20, 2026 at 04:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: move hardware offload step after building the chain blob Allocate the chain blob before the ruleset offload to reduce chances of entering an inconsistent state where the offloaded ruleset in the nic and the software ruleset differ.
Title netfilter: nf_tables: move hardware offload step after building the chain blob
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:52:50.424Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:54.943

Modified: 2026-09-18T18:17:40.363

Link: CVE-2026-90062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses