← All Advisories

CVE-2026-98320

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98320

Key Details

CVECVE-2026-98320
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: hold reference on ct until flow is released

nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe

semantics also allow to refer to the wrong conntrack from the flowtable

datapath. Hold reference on ct until flow is released after rcu grace

period.

Add rcu_barrier() on module exit path, to ensure pending flow entries

are release before module goes away. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98320
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98320