← All Advisories

CVE-2026-97998

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97998

Key Details

CVECVE-2026-97998
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_log: cope with concurrent instance destruction

Instances are refcounted. However, only memory release happens on the

1 -> 0 transition; the unlink from hashes can occur with any refcount.

Uncooperative userspace can force a situation where a queue is pending

for destruction from netlink event while a different socket with same

portid processes an UNBIND request.

With right timing, this will unhash the instance again:

Oops: general protection fault, [..]

Call Trace:

<TASK>

nfulnl_recv_config+0x31a/0xd50

nfnetlink_rcv_msg+0x7c2/0xeb0 (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97998
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97998