netfilter: nf_tables: make nft_object rhltable per table

Summary

CVECVE-2026-74565
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 13:18:02 UTC
Updated2026-08-15 13:18:02 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: make nft_object rhltable per table The nft_object rhltable is global, this allows for accessing objects that are being dismangled from lookup path by other existing netns. Given the nft_obj_destroy() releases the object inmediately, this might lead to use-after-free of these objects that are being released. Make the existing rhltable per table to address this issue to deal with with the nft_rcv_nl_event() path too. Update nft_obj_lookup() to take the table as non-const, otherwise, compiler complains when passing the objname_ht to rhltable_lookup().

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 4d44175aa5bb5f68772b1eb0306554812294ca52 1948e4f85b855618b5b9a27265f98d816f4cb7cb git Not specified
CNA Linux Linux affected 4d44175aa5bb5f68772b1eb0306554812294ca52 63ba12b664a2cd3220ed43e22c717715f4cc2ae8 git Not specified
CNA Linux Linux affected 4d44175aa5bb5f68772b1eb0306554812294ca52 7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af git Not specified
CNA Linux Linux affected 4d44175aa5bb5f68772b1eb0306554812294ca52 f4f699790590bd0896c48a71e9232a65198f92f0 git Not specified
CNA Linux Linux affected 5.1 Not specified
CNA Linux Linux unaffected 5.1 semver Not specified
CNA Linux Linux unaffected 6.12.103 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.44 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.8 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc6 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/f4f699790590bd0896c48a71e9232a65198f92f0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/63ba12b664a2cd3220ed43e22c717715f4cc2ae8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1948e4f85b855618b5b9a27265f98d816f4cb7cb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report