Impact
The flaw lies in the Linux kernel’s netfilter flowtable module, where a conntrack reference is released prematurely. The nf_ct_put() function immediately frees the conntrack extension area while the flowtable datapath may still reference it. Because RCU (Read-Copy-Update) semantics allow reads of stale pointers, an attacker can trigger a use‑after‑free scenario, potentially corrupting memory or achieving arbitrary code execution with kernel privileges. The patch, introduced by holding a reference on the conntrack until the flow is fully released after the RCU grace period, fixes this reuse violation and prevents the unsafe dereference. At the module exit path, adding an rcu_barrier() guarantees that all pending flow entries are released before the module is unloaded, eliminating the race condition. The weakness is a classic use‑after‑free pattern; it is a serious kernel bug because it operates at privilege level zero. The potential impact includes denial of service, memory corruption, or escalation of privileges if an attacker can trigger or observe the fault. Given the removal of the flaw in the patch commit, the main risk is running kernel releases that predate the fix. A system that still deploys those kernels can be targeted by exploiting the reference‑counting bug.
Affected Systems
The issue is present in the Linux kernel’s netfilter flowtable code. All Linux kernel builds that include the affected netfilter module and do not incorporate the recent commit (identified by the SHA references in the advisory) are vulnerable. Specific product names are Linux, Linux Kernel. Exact affected versions are not listed, so any kernel older than the patched commit could be impacted.
Risk and Exploitability
Because the vulnerability relies on a use‑after‑free inside the network stack, the gate for exploitation is a privileged process or a crafted network flow that forces the kernel to release the conntrack while the flowtable is still active. The CVSS score is not provided, but the nature of the flaw suggests high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, indicating limited public exploitation data. Nevertheless, the kernel level impact warrants immediate attention. The likely attack vector is through malformed or malicious ICMP/VPN traffic that triggers the conntrack release while a flow entry exists, or via a crafted packet to a system with an outdated kernel.
OpenCVE Enrichment