In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: move hardware offload step after building the chain blob Allocate the chain blob before the ruleset offload to reduce chances of entering an inconsistent state where the offloaded ruleset in the nic and the software ruleset differ.
https://git.kernel.org/stable/c/d5497644329d3a01e951aba76561bbd883ff6b0c
https://git.kernel.org/stable/c/b1881d362e1924b66f6016c3efd28807032b41bf
https://git.kernel.org/stable/c/923f824f30faebc5560c3061a595063cecdbdbb8
https://git.kernel.org/stable/c/79eafe22ab0a650996da2b3e5d94a12c3e16f3aa
https://git.kernel.org/stable/c/6e7ad6e69be4751ab2476042c70c600bdaa8d4f2
https://git.kernel.org/stable/c/6a7d3b074cfbb64513f5f92d60ab1b216ae98076
https://git.kernel.org/stable/c/52febaf1d311d6ede312b2ec7692a309714f9554
https://git.kernel.org/stable/c/309acbab74e46114246bf4346c9b60b3d8cb4fcd