CVE-2026-93288

Summary

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state

sashiko reports: "nfnl_log_net_exit() calls nf_log_unset(), which clears the logger pointer without an RCU grace period. Immediately after, ops_free_list() frees the per-net state while concurrent packets might still be executing nf_log_packet() under rcu_read_lock()."

Clear the pointer via .pre_exit to make sure rcu readers have completed before pernet storage is free'd. The change in nf_log_syslog.c is only done for consistency: it doesn't use pernet data.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f4461654374576e9d5d0245fd534c46ad8509051affected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dc20050b6b12ca58066715d088e1a537535d938daffected
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 33d1469b0124cc0baaea7a2032123b77a81e0940affected
LinuxLinux0 < 6.12.111affected
LinuxLinux0 < 6.18.53affected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References