UNKNOWN NVD
CVE-2026-98320
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: hold reference on ct until flow is released nf_ct_put() releases the
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: hold reference on ct until flow is released
nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe
semantics also allow to refer to the wrong conntrack from the flowtable
datapath. Hold reference on ct until flow is released after rcu grace
period.
Add rcu_barrier() on module exit path, to ensure pending flow entries
are release before module goes away.
References
- https://git.kernel.org/stable/c/12c1ac230f4ca16e0017b62a963ab75e0b48074f
- https://git.kernel.org/stable/c/61c6688be282277c6e91ab286a7acd0ae8681ac6
- https://git.kernel.org/stable/c/8274cdc5f9c57e17ed77fc4ba76212536c840f25
- https://git.kernel.org/stable/c/93ff1594be1aad4da364462dd8db050ebcfda2de
- https://git.kernel.org/stable/c/a43cd2b67b91e943273c913237a7a88c50cdcfbc
This unknown severity vulnerability was published on 2026-10-06 via NVD.
vulnfeed aggregates 11356 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.