Race condition in Linux kernel - CVE-2026-53269
Published: June 26, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the synproxy hook reference counting logic in netfilter when concurrently adding the first iptables target or nftables expression. A local user can trigger concurrent registration or teardown operations to cause a denial of service.
The issue affects on-demand netfilter hook registration performed by the SYNPROXY infrastructure from both iptables and nftables frontends.
How to mitigate CVE-2026-53269
Sources
- https://git.kernel.org/stable/c/0ec9ddc1bda261a2c57636c74c8b4e53000102c9
- https://git.kernel.org/stable/c/0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88
- https://git.kernel.org/stable/c/2fcba19caaeb2a33017459d3430f057967bb91b6
- https://git.kernel.org/stable/c/56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389
- https://git.kernel.org/stable/c/640441348258220e78daed40528b85b8afcedab6
- https://git.kernel.org/stable/c/aaf80701dc2f7a48fe543961e21f8ca3924d587c
- https://git.kernel.org/stable/c/debc57b83d5b323df74bf010c8d50fe26ad2ed6b
- https://git.kernel.org/stable/c/fbf0591275f50eae5733c3d7a8cd6c1e79933ffa