๐Ÿ” CVE Alert

CVE-2026-74660

UNKNOWN 0.0

netfilter: ebt_nflog: pin the NFLOG backend

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebt_nflog: pin the NFLOG backend nf_log_unregister() runs after the per-net teardown so its final RCU grace period also drains readers that obtained the logger from a per-net binding. However, ebt_nflog passes an explicit ULOG log type to nf_log_packet() without holding a reference on the selected logger module, unlike the xt_NFLOG and nft_log frontends. An ebtables nflog rule can therefore remain callable while nfnetlink_log is unloaded. The resulting interleaving is: CPU 0 CPU 1 nfnetlink_log_fini() unregister_pernet_subsys() kfree(nfnl_log_pernet(net)) ebt_nflog_tg() nf_log_packet() nfulnl_log_packet() instance_lookup_get_rcu() The global ULOG logger is still registered at this point, so CPU 1 dereferences the per-net state after CPU 0 has freed it. KASAN reported: BUG: KASAN: slab-use-after-free in instance_lookup_get_rcu Read of size 8 at addr ff110001052e6210 by task poc/92 Call Trace: instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log] nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log] nf_log_packet+0x204/0x300 ebt_nflog_tg+0x351/0x550 ebt_do_table+0xedf/0x22b0 Allocated by task 90: __kmalloc_noprof+0x186/0x470 ops_init+0x6d/0x420 register_pernet_operations+0x2f6/0x670 register_pernet_subsys+0x23/0x40 Freed by task 93: kfree+0x131/0x3c0 ops_undo_list+0x3e3/0x700 unregister_pernet_operations+0x232/0x490 unregister_pernet_subsys+0x1c/0x30 nfnetlink_log_fini+0x34/0x450 [nfnetlink_log] Acquire the ULOG logger module reference when an ebt_nflog rule is validated and release it when the rule is destroyed. Request the NFLOG backend for legacy callers when needed, matching xt_NFLOG. This prevents module teardown until all ebt_nflog rules have stopped using the logger.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
c83fa19603bdaeef17b815713dbbe3230c8a34ee < 3bcce49d617c593c7606083bfdb464a1761fa68d c83fa19603bdaeef17b815713dbbe3230c8a34ee < 394d7939c6b2b9e6bea0844c89efb5913168d898 c83fa19603bdaeef17b815713dbbe3230c8a34ee < 2cac4294f184c9bc19ff82552c62b80498694c39 c83fa19603bdaeef17b815713dbbe3230c8a34ee < 9d8a94b48b393885e7f876c8ef68ed4da5012078 c83fa19603bdaeef17b815713dbbe3230c8a34ee < 6809379a860b9fccbb5435bf08343f6d081ac68d c83fa19603bdaeef17b815713dbbe3230c8a34ee < 47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb c83fa19603bdaeef17b815713dbbe3230c8a34ee < e2ab7e878bdbe80104c879c31fd2d82a476703b8 c83fa19603bdaeef17b815713dbbe3230c8a34ee < 30825970339c107bacaf7f61af90fcdb1f597ca1
Linux / Linux
4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3bcce49d617c593c7606083bfdb464a1761fa68d git.kernel.org: https://git.kernel.org/stable/c/394d7939c6b2b9e6bea0844c89efb5913168d898 git.kernel.org: https://git.kernel.org/stable/c/2cac4294f184c9bc19ff82552c62b80498694c39 git.kernel.org: https://git.kernel.org/stable/c/9d8a94b48b393885e7f876c8ef68ed4da5012078 git.kernel.org: https://git.kernel.org/stable/c/6809379a860b9fccbb5435bf08343f6d081ac68d git.kernel.org: https://git.kernel.org/stable/c/47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb git.kernel.org: https://git.kernel.org/stable/c/e2ab7e878bdbe80104c879c31fd2d82a476703b8 git.kernel.org: https://git.kernel.org/stable/c/30825970339c107bacaf7f61af90fcdb1f597ca1