Junglewise Threat Intelligence

CVE-2026-74565: Linux kernel netfilter use-after-free in nf_tables object lookup

CVE-2026-74565 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's netfilter subsystem (which implements firewall rules and network packet filtering) contained a use-after-free vulnerability in its table object management. A flaw in how objects were looked up across different network namespaces could allow an attacker to access memory after it had been freed, potentially leading to denial of service or privilege escalation.

Technical details

The vulnerability is a use-after-free in the netfilter nf_tables subsystem, specifically in the nft_object lookup path. The root cause is that a global rhltable (resizable hash table) was used for object lookups, allowing concurrent access from multiple network namespaces. When nft_obj_destroy() released an object, other network namespaces could still attempt to access it via the lookup path, creating a classic use-after-free condition. The fix relocates the per-table object hash table (objname_ht) from global scope to per-table scope, eliminating the race condition. Attack precondition: local access with capability to create network namespaces or influence netlink events. The patch was committed upstream as f4f699790590bd0896c48a71e9232a65198f92f0 and backported to stable kernel versions.

Affected products

  • Linux Linux kernel Affected versions include 5.10.x through 6.x; exact vulnerable range determined by when 4d44175aa5bb was merged through f4f699790590bd0896c48a71e9232a65198f92f0

Timeline

  • 2026-08-15: disclosed: CVE-2026-74565 published
  • 2026-07-16: patched: Upstream fix committed as f4f699790590bd0896c48a71e9232a65198f92f0
  • 2026-09-04: patched: Backported to stable kernel 5.10.x and later

References

Related threats