Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: hold reference on ct until flow is released

nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe
semantics also allow to refer to the wrong conntrack from the flowtable
datapath. Hold reference on ct until flow is released after rcu grace
period.

Add rcu_barrier() on module exit path, to ensure pending flow entries
are release before module goes away.
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Kernel Execution
Action: Update Kernel
AI Analysis

Impact

The flaw lies in the Linux kernel’s netfilter flowtable module, where a conntrack reference is released prematurely. The nf_ct_put() function immediately frees the conntrack extension area while the flowtable datapath may still reference it. Because RCU (Read-Copy-Update) semantics allow reads of stale pointers, an attacker can trigger a use‑after‑free scenario, potentially corrupting memory or achieving arbitrary code execution with kernel privileges. The patch, introduced by holding a reference on the conntrack until the flow is fully released after the RCU grace period, fixes this reuse violation and prevents the unsafe dereference. At the module exit path, adding an rcu_barrier() guarantees that all pending flow entries are released before the module is unloaded, eliminating the race condition. The weakness is a classic use‑after‑free pattern; it is a serious kernel bug because it operates at privilege level zero. The potential impact includes denial of service, memory corruption, or escalation of privileges if an attacker can trigger or observe the fault. Given the removal of the flaw in the patch commit, the main risk is running kernel releases that predate the fix. A system that still deploys those kernels can be targeted by exploiting the reference‑counting bug.

Affected Systems

The issue is present in the Linux kernel’s netfilter flowtable code. All Linux kernel builds that include the affected netfilter module and do not incorporate the recent commit (identified by the SHA references in the advisory) are vulnerable. Specific product names are Linux, Linux Kernel. Exact affected versions are not listed, so any kernel older than the patched commit could be impacted.

Risk and Exploitability

Because the vulnerability relies on a use‑after‑free inside the network stack, the gate for exploitation is a privileged process or a crafted network flow that forces the kernel to release the conntrack while the flowtable is still active. The CVSS score is not provided, but the nature of the flaw suggests high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, indicating limited public exploitation data. Nevertheless, the kernel level impact warrants immediate attention. The likely attack vector is through malformed or malicious ICMP/VPN traffic that triggers the conntrack release while a flow entry exists, or via a crafted packet to a system with an outdated kernel.

Generated by OpenCVE AI on October 6, 2026 at 12:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the fix for the netfilter flowtable reference‑counting bug.
  • Ensure that any netfilter modules loaded after kernel upgrade are also up‑to‑date and include the rcu_barrier() change on module exit.
  • If immediate kernel upgrade is not possible, block or throttle packet flows that could trigger the conntrack release until the kernel is patched.
  • Check system logs for possible SIGSEGV or memory corruption events that may indicate exploitation of the bug.

Generated by OpenCVE AI on October 6, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: hold reference on ct until flow is released nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe semantics also allow to refer to the wrong conntrack from the flowtable datapath. Hold reference on ct until flow is released after rcu grace period. Add rcu_barrier() on module exit path, to ensure pending flow entries are release before module goes away.
Title netfilter: flowtable: hold reference on ct until flow is released
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:46:14.757Z

Reserved: 2026-09-25T10:25:14.340Z

Link: CVE-2026-98320

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:23.957

Modified: 2026-10-06T09:18:23.957

Link: CVE-2026-98320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T13:00:15Z

Weaknesses

No weakness.