← All Advisories

CVE-2026-97609

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97609

Key Details

CVECVE-2026-97609
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: cttimeout: prevent UAF during module unload

nf_ct_set_timeout() protects the timeout hook dereference and policy lookup

with rcu_read_lock(). cttimeout_exit(), however, unregisters the per-net

operations before it clears the hook.

This allows the following interleaving:

CPU 0 CPU 1

cttimeout_exit() nf_ct_set_timeout()

unregister_pernet_subsys() rcu_read_lock()

kfree(pernet) h = nf_ct_timeout_hook

h->timeout_find_get()

nfct_timeout_pernet()

The hook still points to ctnl_timeout_find_get() when CPU 1 looks up the

already freed per-net timeout list. KASAN reported:

BUG: KASAN: slab-use-after-free in ctnl_timeout_find_get

Read of size 8 by task poc/90

Call Trace:

ctnl_timeout_find_get+0x271/0x2a0 [nfnetlink_cttimeout]

nf_ct_set_timeout+0x7b/0x3c0

xt_ct_tg_check+0x724/0xb20

xt_check_target+0x234/0xa90

do_ipt_set_ctl+0x570/0x1270

Allocated by task 89:

__kmalloc_noprof+0x16e/0x460

ops_init+0x6d/0x420

register_pernet_operations+0x2f6/0x670

Freed by task 91:

kfree+0x131/0x390

ops_undo_list+0x3d4/0x730

unregister_pernet_operations+0x232/0x490

unregister_pernet_subsys+0x1c/0x30

cttimeout_exit+0x52/0x970 [nfnetlink_cttimeout]

Clear the hook and wait for existing readers before unregistering the

per-net operations. This blocks new policy lookups and ensures readers that

observed the hook finish before the per-net storage is freed. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97609
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97609