CVE-2026-53000

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
15/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfilter: nat: use kfree_rcu to release ops<br /> <br /> Florian Westphal says:<br /> <br /> "Historically this is not an issue, even for normal base hooks: the data<br /> path doesn&amp;#39;t use the original nf_hook_ops that are used to register the<br /> callbacks.<br /> <br /> However, in v5.14 I added the ability to dump the active netfilter<br /> hooks from userspace.<br /> <br /> This code will peek back into the nf_hook_ops that are available<br /> at the tail of the pointer-array blob used by the datapath.<br /> <br /> The nat hooks are special, because they are called indirectly from<br /> the central nat dispatcher hook. They are currently invisible to<br /> the nfnl hook dump subsystem though.<br /> <br /> But once that changes the nat ops structures have to be deferred too."<br /> <br /> Update nf_nat_register_fn() to deal with partial exposition of the hooks<br /> from error path which can be also an issue for nfnetlink_hook.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.14 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*