{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90062","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.784Z","datePublished":"2026-09-17T16:05:45.853Z","dateUpdated":"2026-09-18T17:52:50.424Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:52:50.424Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: move hardware offload step after building the chain blob\n\nAllocate the chain blob before the ruleset offload to reduce chances of\nentering an inconsistent state where the offloaded ruleset in the nic\nand the software ruleset differ."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The trigger is a local NETLINK_NETFILTER batch (NFT_MSG_NEWCHAIN/NFT_MSG_NEWRULE with NFT_CHAIN_HW_OFFLOAD on an NFPROTO_NETDEV ingress chain) delivered via sendmsg into nfnetlink_rcv → nfnetlink_rcv_batch → nf_tables_commit, which called nft_flow_rule_offload_commit before nf_tables_commit_chain_prepare. No remote protocol payload carries this transaction.\nAC:L - The attacker controls the batch so nft_flow_rule_offload_commit can FLOW_BLOCK_BIND/FLOW_CLS_REPLACE first, then nf_tables_commit_chain_prepare's kvmalloc of chain->blob_next (or nf_tables_commit_audit_alloc) fails; they size that blob independently by adding NEWRULE/DELRULE on a large chain in the same commit, or by exhausting kernel memory beforehand. No victim-owned race is required.\nPR:L - nfnetlink_rcv() accepts the batch only after netlink_net_capable(skb, CAP_NET_ADMIN), which tests sock_net(skb->sk)->user_ns. Unprivileged processes obtain that capability with unshare -Urn, and containers already holding NET_ADMIN plus an offload-capable VF/representor can drive nft_chain_offload_support/ndo_setup_tc, so init-namespace root is not required.\nUI:N - The attacker opens their own NETLINK_NETFILTER socket and sends the NFT_MSG_BATCH_BEGIN commit that includes the NFT_CHAIN_HW_OFFLOAD chain and rules; no other user must mount media, open a file, or otherwise act.\nS:U - Impact is confined to the host kernel and the same netdev ingress flower offload programmed by nft_flow_rule_offload_commit/nft_flow_offload_bind. This does not cross a VM, IOMMU, or other distinct security authority.\nC:N - After the failed commit, __nf_tables_abort destroys software nft_rule/nft_base_chain objects while leftover FLOW_CLS_REPLACE state stays in the driver; nft_flow_offload_cmd stores cookie as an opaque (unsigned long)rule id used only for later flower lookup, and this path does not copy kernel memory back to userspace or perform an out-of-bounds read.\nI:H - nft_flow_rule_offload_commit can complete FLOW_BLOCK_BIND and FLOW_CLS_REPLACE on the NIC, then nf_tables_commit_chain_prepare/nf_tables_commit_audit_alloc failure returns from nf_tables_commit and __nf_tables_abort never calls nft_flow_rule_offload_abort, so aborted ACCEPT/DROP/mirred flower filters remain in hardware after the software chain blob is rolled back.\nA:H - The same leftover FLOW_CLS_REPLACE/FLOW_BLOCK_BIND keeps hardware DROP filters on ingress and leaves flow_block_cb on the driver's list so a later BIND hits flow_block_cb_is_busy; NEWCHAIN abort then kfree's nft_base_chain in nf_tables_chain_destroy while that bind is still live, which can oops on subsequent ndo_setup_tc or netdev teardown."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/nf_tables_api.c"],"versions":[{"version":"c9626a2cbdb20e26587b3fad99960520a023432b","lessThan":"923f824f30faebc5560c3061a595063cecdbdbb8","status":"affected","versionType":"git"},{"version":"c9626a2cbdb20e26587b3fad99960520a023432b","lessThan":"6e7ad6e69be4751ab2476042c70c600bdaa8d4f2","status":"affected","versionType":"git"},{"version":"c9626a2cbdb20e26587b3fad99960520a023432b","lessThan":"309acbab74e46114246bf4346c9b60b3d8cb4fcd","status":"affected","versionType":"git"},{"version":"c9626a2cbdb20e26587b3fad99960520a023432b","lessThan":"79eafe22ab0a650996da2b3e5d94a12c3e16f3aa","status":"affected","versionType":"git"},{"version":"c9626a2cbdb20e26587b3fad99960520a023432b","lessThan":"52febaf1d311d6ede312b2ec7692a309714f9554","status":"affected","versionType":"git"},{"version":"c9626a2cbdb20e26587b3fad99960520a023432b","lessThan":"d5497644329d3a01e951aba76561bbd883ff6b0c","status":"affected","versionType":"git"},{"version":"c9626a2cbdb20e26587b3fad99960520a023432b","lessThan":"6a7d3b074cfbb64513f5f92d60ab1b216ae98076","status":"affected","versionType":"git"},{"version":"c9626a2cbdb20e26587b3fad99960520a023432b","lessThan":"b1881d362e1924b66f6016c3efd28807032b41bf","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/nf_tables_api.c"],"versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/923f824f30faebc5560c3061a595063cecdbdbb8"},{"url":"https://git.kernel.org/stable/c/6e7ad6e69be4751ab2476042c70c600bdaa8d4f2"},{"url":"https://git.kernel.org/stable/c/309acbab74e46114246bf4346c9b60b3d8cb4fcd"},{"url":"https://git.kernel.org/stable/c/79eafe22ab0a650996da2b3e5d94a12c3e16f3aa"},{"url":"https://git.kernel.org/stable/c/52febaf1d311d6ede312b2ec7692a309714f9554"},{"url":"https://git.kernel.org/stable/c/d5497644329d3a01e951aba76561bbd883ff6b0c"},{"url":"https://git.kernel.org/stable/c/6a7d3b074cfbb64513f5f92d60ab1b216ae98076"},{"url":"https://git.kernel.org/stable/c/b1881d362e1924b66f6016c3efd28807032b41bf"}],"title":"netfilter: nf_tables: move hardware offload step after building the chain blob","x_generator":{"engine":"bippy-1.2.0"}}}}