In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftables: make nftobject rhltable per table
The nftobject rhltable is global, this allows for accessing objects that are being dismangled from lookup path by other existing netns. Given the nftobjdestroy() releases the object inmediately, this might lead to use-after-free of these objects that are being released. Make the existing rhltable per table to address this issue to deal with with the nftrcvnlevent() path too.
Update nftobjlookup() to take the table as non-const, otherwise, compiler complains when passing the objnameht to rhltablelookup().