Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97998— netfilter: nfnetlink_log: cope with concurrent instance destruction

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: netfilter: nfnetlink_log:妥善处理并发实例销毁 实例采用引用计数机制。然而,仅在引用计数从 1 变为 0 时执行内存释放;而从哈希表中移除实例的操作可以在任意引用计数下进行。 非合作的用户空间程序可能引发如下情况:当某个套接字正在处理 UNBIND 请求时,另一个具有相同 portid 的套接字可能因 netlink 事件而触发队列待销毁。 如果时机恰当,这将导致实例被再次从哈希表中移除:

AI Predicted 4.4 Difficulty: Hard EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 0597f2680d666a3bcf101ac0c771ba7e50016bbd< c5c89beaa628d6ac527c6eb2e01b2b52eb417f59 affected
0597f2680d666a3bcf101ac0c771ba7e50016bbd< 042465e7d3d3127e21f04e42c1639e2518b98915 affected
0597f2680d666a3bcf101ac0c771ba7e50016bbd< 291685fc8d2e4cf75ed3a23c810883653f407f46 affected
0597f2680d666a3bcf101ac0c771ba7e50016bbd< 3161186a2ff81288e9a5f35daf1911153764ecae affected
0597f2680d666a3bcf101ac0c771ba7e50016bbd< 0234d7ca0317be0a623300e1693cd794bbfdf8af affected
0597f2680d666a3bcf101ac0c771ba7e50016bbd< 1a7a8ac9a9f0ad0d410c901cb6f233833518844c affected
0597f2680d666a3bcf101ac0c771ba7e50016bbd< e2dd0f1f8c4e6334699ea6382e52f6da0c7e45eb affected
0597f2680d666a3bcf101ac0c771ba7e50016bbd< 387d744fa7e499d2c3748a4e60e02ebb24e7fb16 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97998

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: nfnetlink_log: cope with concurrent instance destruction
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: cope with concurrent instance destruction Instances are refcounted. However, only memory release happens on the 1 -> 0 transition; the unlink from hashes can occur with any refcount. Uncooperative userspace can force a situation where a queue is pending for destruction from netlink event while a different socket with same portid processes an UNBIND request. With right timing, this will unhash the instance again: Oops: general protection fault, [..] Call Trace: <TASK> nfulnl_recv_config+0x31a/0xd50 nfnetlink_rcv_msg+0x7c2/0xeb0
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0597f2680d666a3bcf101ac0c771ba7e50016bbd ~ c5c89beaa628d6ac527c6eb2e01b2b52eb417f59 -
Linux Linux 2.6.14 -

II. Public POCs for CVE-2026-97998

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97998

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97998 (8)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-97941 7.8 HIGH mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-97937 7.8 HIGH ftrace: fork: Initialize function graph state before copy_exec_state()
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97998

No comments yet


Leave a comment