In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: add hook transactions for device deletions
Restore the flag that indicates that the hook is going away, ie. NFTHOOKREMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase.
The existing approach that moves the hook from the basechain/flowtable hooklist to transaction hooklist breaks netlink dump path readers of this RCU-protected list.
It should be possible use an array for nfttranshook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place.
Note that the nfttranschainhooks() list contains a list of struct nfttranshook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nfthook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nfttranshook for consistency.
This patch also adapts the event notification path to deal with the list of hook transactions.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63858.json",
"cna_assigner": "Linux"
}