Race condition in Linux kernel - CVE-2026-97998
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the nfnetlink_log instance destruction handler when concurrently processing a netlink close event and an UNBIND request from sockets using the same port ID. A local user can trigger concurrent instance destruction and unbinding to cause a denial of service.