Junglewise Threat Intelligence

CVE-2026-80744: Linux kernel netfilter nf_tables_offload spurious warning on memory allocation failure

CVE-2026-80744 · Severity: info · Published 2026-09-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A kernel driver for the Linux netfilter packet filtering subsystem was emitting warning messages whenever memory allocation failed during transaction rollback, even though such failures are expected under normal low-memory conditions. While this does not represent an exploitable vulnerability, the spurious warnings complicate system administration and obscure genuine kernel bugs.

Technical details

The vulnerability is a logic error in the nft_flow_rule_offload_abort() function in net/netfilter/nf_tables_offload.c, where a WARN_ON_ONCE(err) macro was triggered unconditionally on any error during offload transaction rollback, including expected -ENOMEM conditions. The root cause is that memory allocation failures (via flow_block_cb_alloc()) during netlink processing of nftables commands can legitimately fail under memory pressure, yet the code treated all errors as unexpected bugs. The fix is to refine the warning condition to WARN_ON_ONCE(err && err != -ENOMEM), suppressing warnings only for memory allocation failures while preserving warnings for genuine unexpected errors. This is a defensive coding improvement with no security impact; patches have been applied to mainline and stable kernels.

Affected products

  • Linux Linux kernel 5.10 and mainline

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched

Related threats