CVE-2026-98320

high

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: hold reference on ct until flow is released nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe semantics also allow to refer to the wrong conntrack from the flowtable datapath. Hold reference on ct until flow is released after rcu grace period. Add rcu_barrier() on module exit path, to ensure pending flow entries are release before module goes away.

References

https://git.kernel.org/stable/c/eed6997e8dc40593a539fcc722e7ed51b18db86c

https://git.kernel.org/stable/c/e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d

https://git.kernel.org/stable/c/d9e6175a3ee48209ee65f294fc567b4e16b29b74

https://git.kernel.org/stable/c/a43cd2b67b91e943273c913237a7a88c50cdcfbc

https://git.kernel.org/stable/c/93ff1594be1aad4da364462dd8db050ebcfda2de

https://git.kernel.org/stable/c/8274cdc5f9c57e17ed77fc4ba76212536c840f25

https://git.kernel.org/stable/c/61c6688be282277c6e91ab286a7acd0ae8681ac6

https://git.kernel.org/stable/c/12c1ac230f4ca16e0017b62a963ab75e0b48074f

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93305

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0022