KernelScan.io

HIGH Introduced in 5.15

netfilter ebtables TableRemoval Race

CVE-2026-64077

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: move to two-stage removal scheme Like previous patches for x_tables, follow same pattern in ebtables. We can't reuse xt helpers: ebt_table struct layout is incompatible. table->ops assignment is now done while still holding the ebt mutex to make sure we never expose partially-filled table struct.

02

Engine v0.4.0

Risk summary

A race condition in the Linux kernel's ebtables subsystem allows a local user with CAP_NET_ADMIN (obtainable via user namespaces) to trigger a use-after-free by racing table registration/unregistration with packet processing hooks. Successful exploitation could lead to arbitrary kernel memory corruption, enabling privilege escalation or system crash. The vulnerability affects kernels from 5.15 onward where ebtables tables are lazily registered per network namespace.

Affectednet/bridge/netfilter/ebtables.c (ebtables netfilter subsystem)

Vulnerability analysis

The root cause is a TOCTOU/race condition introduced by commit 87663c39f898 in the ebtables lazy-registration scheme. In the original buggy code, ebt_register_table() would add the table to the per-netns list and release the ebt_mutex before assigning table->ops and calling nf_register_net_hooks(). This created a window where a partially-initialized table struct (with ops not yet assigned) was visible to other threads. Concurrently, ebt_unregister_table_pre_exit() and ebt_unregister_table() used a two-step lookup (__ebt_find_table) that released and re-acquired the mutex between finding and operating on the table, creating a window for use-after-free if the table was freed between the two operations. The fix implements a proper two-stage removal scheme: (1) table->ops is now assigned while still holding ebt_mutex before the table is added to the live list, preventing exposure of partially-filled structs; (2) a new dead_tables list is introduced so that ebt_unregister_table_pre_exit() atomically moves the table from tables to dead_tables (under the mutex) before unregistering hooks, and ebt_unregister_table() then operates only on dead_tables; (3) the unregister order in module exit functions is swapped to call ebt_unregister_template() before unregister_pernet_subsys(). The attack surface requires CAP_NET_ADMIN, which is obtainable by unprivileged users via user namespaces on most Linux distributions, making this reachable from unprivileged local processes.

03

BranchIntroducedFixed inPatch commit
6.185.156.18.34739d5dac7b2d
mainline5.157.1b7f0544d86d4
7.05.157.0.11ef395579a763