HIGH Introduced in 5.15
netfilter xtables TableExit UAF
CVE-2026-64078
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: add and use xtables_unregister_table_exit Previous change added xtables_unregister_table_pre_exit to detach the table from the packetpath and to unlink it from the active table list. In case of rmmod, userspace that is doing set/getsockopt for this table will not be able to re-instantiate the table: 1. The larval table has been removed already 2. existing instantiated table is no longer on the xt pernet table list. This adds the second stage helper: unlink the table from the dying list, free the hook ops (if any) and do the audit notification. It replaces xt_unregister_table().
02KernelScan AI Analysis
Risk summary
A use-after-free vulnerability exists in the Linux kernel's netfilter x_tables subsystem during module removal (rmmod) or network-namespace teardown. When a netfilter table is being unregistered in two stages while userspace is concurrently performing setsockopt/getsockopt operations, the table can be freed while still accessible, leading to memory corruption. A local user with CAP_NET_ADMIN (obtainable via an unprivileged user namespace on default kernels) can exploit this race to corrupt kernel heap memory, potentially leading to arbitrary code execution or kernel panic.
Vulnerability analysis
The root cause is a race condition in the two-phase netfilter table unregistration process introduced by fdacd57c79b7. The first stage (xt_unregister_table_pre_exit) detaches the table from the packet path and, in the buggy code, removes it from the active table list. The second stage (ipt_unregister_table_exit / ip6t_unregister_table_exit / arpt_unregister_table) then attempts to locate the table via xt_find_table() in order to free it. Because the table is no longer on the active list, xt_find_table() returns NULL, causing the table object (and its xt_table_info) to be leaked—or, in concurrent paths, potentially freed while setsockopt/getsockopt callers still hold references to the private data. The fix introduces a per-address-family dead_tables list. xt_unregister_table_pre_exit() now moves the table to this dead list (via list_move), and the new xt_unregister_table_exit() finds it there, performs audit notification, frees the hook ops, and returns the table pointer so the caller can safely free it after any required RCU grace period. This closes the race and prevents both the leak and the use-after-free.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 5.15 | 7.1 | b4597d5fd7d2 |
| 7.0 | 5.15 | 7.0.11 | 8026e5163cca |
| 6.18 | 5.15 | 6.18.34 | 86ee5bc9c0f0 |