Junglewise Threat Intelligence

CVE-2026-64189: Linux Kernel use-after-free in netfilter ipset during list resize

CVE-2026-64189 · Severity: info · CVSS 7.8 · Published 2026-07-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem, specifically within the ipset utility used for managing firewall rules. A race condition allows a local attacker to trigger a system crash or potentially execute unauthorized code by manipulating IP set lists while they are being exported. This could lead to a complete denial of service or unauthorized access to sensitive system memory.

Technical details

A use-after-free vulnerability exists in the Linux kernel netfilter ipset component due to a race condition between ip_set_dump_do/ip_set_dump_done and ip_set_list resizing. The dump functions access the ip_set_list array via ip_set_ref_netlink() without proper RCU read-side critical sections or mutex protection. If a concurrent ip_set_create() operation triggers an array resize, it may free the old array while the dump process is still indexing into it. This results in a slab-use-after-free, which can be observed as a KASAN-detected invalid memory access or a general protection fault leading to a kernel panic. The fix involves wrapping the affected array loads in rcu_read_lock() and rcu_read_unlock() to ensure the array is not freed during the dump operation.

Affected products

  • Linux Linux Kernel 4.19.5 to 7.1

Timeline

  • 2026-06-24: disclosed: Vulnerability reported by Weiming Shi
  • 2026-06-30: patched: Initial patch committed to stable tree
  • 2026-07-20: advisory: NVD publication date

References

Related threats