SB20260905106 - Use-after-free in Linux kernel netfilter
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-80837)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free write.
The vulnerability exists due to a race condition in the nf_tables object notification queue when sending packets through a chain that references a depleted quota object. A remote attacker can send packets through the affected chain to trigger a use-after-free write.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/68de7f3a38acab355c24114f77bf00d3094ce4da
- https://git.kernel.org/stable/c/6fa88d11983c6fe693c13ed7c5b3b75ae9f39de6
- https://git.kernel.org/stable/c/7904b94768e983bcb2be34a8d6d1f3450f5b838b
- https://git.kernel.org/stable/c/df86c0e84025be8b6dd572a20852698927aa666b
- https://git.kernel.org/stable/c/e97e2d6d0b150fd78be573f9fdf193f204d9334e