Executive brief
A vulnerability was identified in the Linux kernel's networking subsystem that could allow a local user to cause system instability. The issue occurs when multiple security rules are added at the same time, potentially leading to a system crash or unpredictable behavior in the firewall. This affects systems using the SYNPROXY feature to protect against network attacks.
Technical details
A race condition exists in net/netfilter/nf_synproxy_core.c within the Linux kernel. The synproxy infrastructure registers netfilter hooks on-demand when a user adds the first iptables target or nftables expression. If multiple frontends (iptables/nftables) attempt to initialize synproxy concurrently, they can race during hook registration and reference counting. This lack of serialization can lead to incorrect reference counts or double-registration of hooks. The fix introduces a global mutex (synproxy_mutex) to serialize access to the reference counting control blocks during initialization and cleanup.
Affected products
- Linux Linux Kernel 5.3 to 6.13
Timeline
- 2026-05-26: patched: Initial patch authored by Fernando Fernandez Mancera
- 2026-06-25: advisory: CVE-2026-53269 published by NVD
References
- https://git.kernel.org/stable/c/0ec9ddc1bda261a2c57636c74c8b4e53000102c9
- https://git.kernel.org/stable/c/0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88
- https://git.kernel.org/stable/c/2fcba19caaeb2a33017459d3430f057967bb91b6
- https://git.kernel.org/stable/c/56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389
- https://git.kernel.org/stable/c/640441348258220e78daed40528b85b8afcedab6
- https://git.kernel.org/stable/c/aaf80701dc2f7a48fe543961e21f8ca3924d587c
- https://git.kernel.org/stable/c/debc57b83d5b323df74bf010c8d50fe26ad2ed6b