SB20260919161 - Incorrect behavior order in Linux kernel netfilter
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect behavior order (CVE-ID: CVE-2026-90062)
CWE-ID: CWE-696 - Incorrect Behavior Order
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause an inconsistent state between hardware-offloaded and software rulesets.
The vulnerability exists due to incorrect behavior order in nf_tables commit processing when committing rulesets with hardware flow-rule offload. A local user can commit a ruleset with hardware flow-rule offload to cause an inconsistent state between hardware-offloaded and software rulesets.
The inconsistency can occur if chain blob preparation fails after the hardware ruleset has been offloaded.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/309acbab74e46114246bf4346c9b60b3d8cb4fcd
- https://git.kernel.org/stable/c/52febaf1d311d6ede312b2ec7692a309714f9554
- https://git.kernel.org/stable/c/6a7d3b074cfbb64513f5f92d60ab1b216ae98076
- https://git.kernel.org/stable/c/6e7ad6e69be4751ab2476042c70c600bdaa8d4f2
- https://git.kernel.org/stable/c/79eafe22ab0a650996da2b3e5d94a12c3e16f3aa
- https://git.kernel.org/stable/c/923f824f30faebc5560c3061a595063cecdbdbb8
- https://git.kernel.org/stable/c/b1881d362e1924b66f6016c3efd28807032b41bf
- https://git.kernel.org/stable/c/d5497644329d3a01e951aba76561bbd883ff6b0c