KernelScan.io

HIGH

netfilter nft_hook UAF

CVE-2026-63858

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.9MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: add hook transactions for device deletions Restore the flag that indicates that the hook is going away, ie. NFT_HOOK_REMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase. The existing approach that moves the hook from the basechain/flowtable hook_list to transaction hook_list breaks netlink dump path readers of this RCU-protected list. It should be possible use an array for nft_trans_hook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place. Note that the nft_trans_chain_hooks() list contains a list of struct nft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nft_trans_hook for consistency. This patch also adapts the event notification path to deal with the list of hook transactions.

02

Engine v0.4.0

Risk summary

A local user with CAP_NET_ADMIN (obtainable via user namespaces on most distributions) can trigger a use-after-free in the nf_tables hook management code by deleting a netdev chain or flowtable device hook while a concurrent netlink dump is reading the same RCU-protected hook list. Successful exploitation can lead to arbitrary kernel memory read/write and privilege escalation. The race window makes exploitation difficult but not impossible.

Affectednet/netfilter/nf_tables_api.c (nf_tables netdev hook management)

Vulnerability analysis

The root cause is that the original code moved nft_hook objects from the basechain/flowtable hook_list to the transaction's hook_list during the preparation phase of a DELCHAIN or DELFLOWTABLE operation. Because the hook_list is RCU-protected and concurrently read by the netlink dump path (nf_tables_dump_chains, nf_tables_dump_flowtable), removing an entry from the list while a reader holds an RCU read lock can cause the reader to dereference a freed or repurposed nft_hook object — a classic use-after-free via RCU list manipulation. The fix introduces a new nft_trans_hook wrapper struct and a NFT_HOOK_REMOVE flag: instead of moving hooks out of the live list during preparation, hooks remain in place but are marked with NFT_HOOK_REMOVE so that lookup functions skip them. A separate transaction list of nft_trans_hook objects tracks which hooks are pending deletion. The actual unregistration and freeing only happens at commit time via nft_netdev_unregister_trans_hook / nft_flowtable_unregister_trans_hook, after which nft_netdev_hook_unlink_free_rcu safely removes the hook from the live list under RCU. Abort path calls nft_trans_delhook_abort to clear the flag and free the wrapper. The attack surface requires CAP_NET_ADMIN, which is obtainable in a user namespace on most Linux distributions, making this reachable by unprivileged local users. A concurrent netlink dump racing with a hook deletion transaction is needed, making AC:High appropriate.

03

BranchIntroducedFixed inPatch commit
5.155.15.475.1610f79dbd7719
5.175.17.155.18—
5.185.18.45.19—
7.0—7.0.10—
mainline—7.1—
5.105.10.1225.114e69bfb32b2d