Executive brief
A vulnerability in the Linux kernel's networking subsystem could cause a system crash (kernel oops) when certain network address translation (NAT) modules are unloaded. This occurs because the system fails to properly clean up internal references to the module's code before it is removed from memory. An attacker with high-level system privileges could potentially trigger this to disrupt operations or cause a denial-of-service.
Technical details
A use-after-free vulnerability exists in the Linux kernel netfilter subsystem (nf_conntrack). NAT helpers like nf_nat_h323 store raw pointers to module text in the 'expectfn' field. When a module is unloaded, nf_ct_helper_expectfn_unregister() unlinks the callback descriptor but fails to purge the expectation table. Consequently, if a new connection arrives that matches a pending expectation, the kernel attempts to execute code at a stale pointer address within the already freed module memory. This results in a kernel oops. Exploitation requires CAP_SYS_MODULE privileges to unload the affected NAT helpers while expectations are active. The fix introduces nf_ct_helper_expectfn_destroy() to iterate through and remove these stale expectations during module cleanup.
Affected products
- Linux Linux Kernel f587de0e2feb to fbfde85308b9
Timeline
- 2026-06-03: other: Patch authored
- 2026-07-01: disclosed: CVE published
References
- https://git.kernel.org/stable/c/29d8cc44bbdf7b83a1929912214afe6643c1b4f1
- https://git.kernel.org/stable/c/9d017671dcfcec23321fb7962dea624f9e71ddb1
- https://git.kernel.org/stable/c/bf8c0b5dd203be94c2ad50e264cec19267c6bd39
- https://git.kernel.org/stable/c/c3009418f9fa1dcb3eb86f4d8c92583537b5faa3
- https://git.kernel.org/stable/c/f92c90a2a3e6ff6f9f7fe88fde9004b4ca8f956d
- https://git.kernel.org/stable/c/fbfde85308b99938a6092c48753214d190ece48d