KernelScan.io

HIGH Introduced in 5.15

netfilter xtables TableExit UAF

CVE-2026-64078

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: add and use xtables_unregister_table_exit Previous change added xtables_unregister_table_pre_exit to detach the table from the packetpath and to unlink it from the active table list. In case of rmmod, userspace that is doing set/getsockopt for this table will not be able to re-instantiate the table: 1. The larval table has been removed already 2. existing instantiated table is no longer on the xt pernet table list. This adds the second stage helper: unlink the table from the dying list, free the hook ops (if any) and do the audit notification. It replaces xt_unregister_table().

02

Engine v0.4.0

Risk summary

A use-after-free vulnerability exists in the Linux kernel's netfilter x_tables subsystem during module removal (rmmod) or network-namespace teardown. When a netfilter table is being unregistered in two stages while userspace is concurrently performing setsockopt/getsockopt operations, the table can be freed while still accessible, leading to memory corruption. A local user with CAP_NET_ADMIN (obtainable via an unprivileged user namespace on default kernels) can exploit this race to corrupt kernel heap memory, potentially leading to arbitrary code execution or kernel panic.

Affectednet/netfilter/x_tables.c (netfilter x_tables)

Vulnerability analysis

The root cause is a race condition in the two-phase netfilter table unregistration process introduced by fdacd57c79b7. The first stage (xt_unregister_table_pre_exit) detaches the table from the packet path and, in the buggy code, removes it from the active table list. The second stage (ipt_unregister_table_exit / ip6t_unregister_table_exit / arpt_unregister_table) then attempts to locate the table via xt_find_table() in order to free it. Because the table is no longer on the active list, xt_find_table() returns NULL, causing the table object (and its xt_table_info) to be leaked—or, in concurrent paths, potentially freed while setsockopt/getsockopt callers still hold references to the private data. The fix introduces a per-address-family dead_tables list. xt_unregister_table_pre_exit() now moves the table to this dead list (via list_move), and the new xt_unregister_table_exit() finds it there, performs audit notification, frees the hook ops, and returns the table pointer so the caller can safely free it after any required RCU grace period. This closes the race and prevents both the leak and the use-after-free.

03

BranchIntroducedFixed inPatch commit
mainline5.157.1b4597d5fd7d2
7.05.157.0.118026e5163cca
6.185.156.18.3486ee5bc9c0f0