Use-after-free in Linux kernel - CVE-2026-80837
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger a use-after-free write.
The vulnerability exists due to a race condition in the nf_tables object notification queue when sending packets through a chain that references a depleted quota object. A remote attacker can send packets through the affected chain to trigger a use-after-free write.
Affected software
How to mitigate CVE-2026-80837
External References
- https://git.kernel.org/stable/c/68de7f3a38acab355c24114f77bf00d3094ce4da
- https://git.kernel.org/stable/c/6fa88d11983c6fe693c13ed7c5b3b75ae9f39de6
- https://git.kernel.org/stable/c/7904b94768e983bcb2be34a8d6d1f3450f5b838b
- https://git.kernel.org/stable/c/df86c0e84025be8b6dd572a20852698927aa666b
- https://git.kernel.org/stable/c/e97e2d6d0b150fd78be573f9fdf193f204d9334e