Sceawere
Vulnerability Detail
CVE-2026-98320UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Linux Netfilter Use-After-Free Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: hold reference on ct until flow is released nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe semantics also allow to refer to the wrong conntrack from the flowtable datapath. Hold reference on ct until flow is released after rcu grace period. Add rcu_barrier() on module exit path, to ensure pending flow entries are release before module goes away.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-06T09:18:23.957Z",
"pubdate": "2026-10-06T09:18:23.957Z",
"executiveSummary": "This vulnerability involves a use-after-free condition within the Linux kernel Netfilter flowtable subsystem. The defect arises due to improper reference counting of conntrack (ct) objects when integrated with flowtables. Because nf_ct_put() immediately releases the associated extension area, the flowtable datapath can incorrectly reference stale conntrack entries due to RCU (Read-Copy-Update) semantics.\nThe impact of this flaw is significant, as it can lead to memory corruption, kernel panics, or potential privilege escalation. An attacker capable of manipulating network traffic could trigger the premature deallocation of conntrack objects, subsequently causing the flowtable to operate on freed memory. This vulnerability affects systems utilizing the Linux kernel's Netfilter flowtable infrastructure. Successful exploitation requires an attacker to generate specific network traffic patterns that trigger the race condition, potentially allowing for arbitrary code execution or system instability within the kernel context.",
"technicalDetails": "The root cause of this vulnerability lies in the lifecycle management of conntrack (ct) objects within the Netfilter flowtable. In the Linux kernel, nf_ct_put() is responsible for decrementing the reference count of a conntrack entry and, if the count reaches zero, immediately freeing the associated memory, including the ct->ext area. The flowtable datapath utilizes RCU semantics to access these entries concurrently. However, the existing implementation failed to maintain a persistent reference on the conntrack object until the flow entry itself was fully released after the RCU grace period.\nThe exploitation flow begins when an entry is added to the flowtable and linked to a conntrack object. If the conntrack entry is marked for destruction or if the reference count is prematurely decremented via nf_ct_put(), the flowtable may retain a pointer to the now-freed memory. Because the flowtable datapath does not increment the reference count correctly, it accesses stale memory locations when processing subsequent packets associated with the flow. This results in a use-after-free scenario where the kernel performs operations on a freed object's structure.\nAn attacker can exploit this by injecting packets that trigger flowtable lookups while simultaneously inducing the destruction of the underlying conntrack entries. By timing these events, the attacker causes the flowtable to perform operations on an address that has been reallocated to a different kernel object, leading to controlled data corruption or execution flow hijacking. The vulnerability is further exacerbated by the potential for race conditions in the module exit path, where pending flow entries might be accessed after the module's code has been unloaded, unless an rcu_barrier() is explicitly invoked.\nThe scope of this vulnerability encompasses the interaction between the conntrack tracking system and the offload flowtable infrastructure. It demonstrates a breakdown in resource ownership, where the flowtable assumes the longevity of the conntrack object without providing the necessary synchronization primitives to guarantee its existence during RCU read cycles. The requirement to hold a reference until the flow is explicitly released ensures that the object remains valid for the duration of its potential use by the datapath, preventing the premature deallocation that facilitates the vulnerability."
}