Executive brief
The Linux kernel's netfilter firewall subsystem contains a vulnerability in chain lookup logic that can cause a rule to reference a deleted chain. This can lead to use-after-free memory issues and kernel warnings, potentially causing system instability or denial of service in environments using netfilter for packet filtering and network address translation.
Technical details
The vulnerability exists in netfilter's nf_tables chain ID lookup function, which fails to validate the generation mask (genmask) when retrieving chains by ID. This allows a rule added within a batch transaction to reference a chain that was deleted in the same batch, resulting in a use-after-free condition. The issue manifests as kernel warnings and potential crashes during chain destruction. The vulnerability requires root/CAP_NET_ADMIN privileges to trigger via netfilter rule manipulation. A fix has been applied to properly validate genmask during chain lookup, ensuring deleted chains cannot be referenced.
Affected products
- Linux Linux kernel 6.4.0 and prior
Timeline
- 2025-10-01: disclosed