{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98320","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.340Z","datePublished":"2026-10-06T08:46:14.757Z","dateUpdated":"2026-10-07T06:50:01.858Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:01.858Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: hold reference on ct until flow is released\n\nnf_ct_put() releases the ct->ext area inmediately, the rcu typesafe\nsemantics also allow to refer to the wrong conntrack from the flowtable\ndatapath. Hold reference on ct until flow is released after rcu grace\nperiod.\n\nAdd rcu_barrier() on module exit path, to ensure pending flow entries\nare release before module goes away."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The freed ct is reached from nf_flow_offload_forward() (nf_ct_acct_update/flow_offload_teardown on flow->ct) but freeing it needs the conntrack killed (nf_ct_is_dying) and flow_offload_del() run; a remote peer only supplies forwarded packets and cannot kill an offloaded ct, so the full trigger needs local nftables/ctnetlink access.\nAC:L - The attacker drives every side of the race: they flood packets through their own flowtable, delete the ct via ctnetlink, and force nf_flow_offload_gc_step()->flow_offload_del() at once by downing the veth (nf_flow_table_gc_cleanup flush_delayed_work). The window is narrow but can be retried indefinitely.\nPR:L - Creating the nftables flowtable, adding veth forwarding and sending IPCTNL_MSG_CT_DELETE need only CAP_NET_ADMIN in a network namespace, which an unprivileged user gets via unshare -Urn.\nUI:N - No victim action is needed; the attacker sets up the flowtable, the traffic and the conntrack/flow teardown entirely within their own namespace.\nS:U - Memory corruption in the host kernel's netfilter flowtable/conntrack objects yields kernel privilege escalation within the same authority; no VM or hardware boundary is crossed.\nC:H - flow_offload_free() dropped the ct reference before the RCU grace period, so in-flight readers dereference ct->ext after nf_conntrack_free() has kfree'd it, or a recycled SLAB_TYPESAFE_BY_RCU nf_conn now owned by another connection - a use-after-free that can be groomed to leak kernel memory.\nI:H - The stale reader writes freed or reused memory: nf_ct_acct_add() does atomic64_add into the freed ct->ext counters, and flow_offload_teardown()/flow_offload_fixup_ct() modify status/timeout of a recycled conntrack, giving heap-corruption primitives.\nA:H - The use-after-free on ct->ext and recycled nf_conn objects in the forwarding softirq can corrupt the slab and crash the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/nf_flow_table_core.c"],"versions":[{"version":"0ff90b6c20340e57616a51ae1a1bf18156d6638a","lessThan":"93ff1594be1aad4da364462dd8db050ebcfda2de","status":"affected","versionType":"git"},{"version":"0ff90b6c20340e57616a51ae1a1bf18156d6638a","lessThan":"eed6997e8dc40593a539fcc722e7ed51b18db86c","status":"affected","versionType":"git"},{"version":"0ff90b6c20340e57616a51ae1a1bf18156d6638a","lessThan":"61c6688be282277c6e91ab286a7acd0ae8681ac6","status":"affected","versionType":"git"},{"version":"0ff90b6c20340e57616a51ae1a1bf18156d6638a","lessThan":"a43cd2b67b91e943273c913237a7a88c50cdcfbc","status":"affected","versionType":"git"},{"version":"0ff90b6c20340e57616a51ae1a1bf18156d6638a","lessThan":"8274cdc5f9c57e17ed77fc4ba76212536c840f25","status":"affected","versionType":"git"},{"version":"0ff90b6c20340e57616a51ae1a1bf18156d6638a","lessThan":"12c1ac230f4ca16e0017b62a963ab75e0b48074f","status":"affected","versionType":"git"},{"version":"0ff90b6c20340e57616a51ae1a1bf18156d6638a","lessThan":"d9e6175a3ee48209ee65f294fc567b4e16b29b74","status":"affected","versionType":"git"},{"version":"0ff90b6c20340e57616a51ae1a1bf18156d6638a","lessThan":"e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/netfilter/nf_flow_table_core.c"],"versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/93ff1594be1aad4da364462dd8db050ebcfda2de"},{"url":"https://git.kernel.org/stable/c/eed6997e8dc40593a539fcc722e7ed51b18db86c"},{"url":"https://git.kernel.org/stable/c/61c6688be282277c6e91ab286a7acd0ae8681ac6"},{"url":"https://git.kernel.org/stable/c/a43cd2b67b91e943273c913237a7a88c50cdcfbc"},{"url":"https://git.kernel.org/stable/c/8274cdc5f9c57e17ed77fc4ba76212536c840f25"},{"url":"https://git.kernel.org/stable/c/12c1ac230f4ca16e0017b62a963ab75e0b48074f"},{"url":"https://git.kernel.org/stable/c/d9e6175a3ee48209ee65f294fc567b4e16b29b74"},{"url":"https://git.kernel.org/stable/c/e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d"}],"title":"netfilter: flowtable: hold reference on ct until flow is released","x_generator":{"engine":"bippy-1.2.0"}}}}