CVE-2026-74565

Source
https://cve.org/CVERecord?id=CVE-2026-74565
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74565.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74565
Downstream
Published
2026-08-15T12:28:07Z
Modified
2026-08-18T03:56:52Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
netfilter: nf_tables: make nft_object rhltable per table
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: make nft_object rhltable per table

The nft_object rhltable is global, this allows for accessing objects that are being dismangled from lookup path by other existing netns. Given the nft_obj_destroy() releases the object inmediately, this might lead to use-after-free of these objects that are being released. Make the existing rhltable per table to address this issue to deal with with the nft_rcv_nl_event() path too.

Update nft_obj_lookup() to take the table as non-const, otherwise, compiler complains when passing the objname_ht to rhltable_lookup().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74565.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4d44175aa5bb5f68772b1eb0306554812294ca52
Fixed
1948e4f85b855618b5b9a27265f98d816f4cb7cb
Fixed
63ba12b664a2cd3220ed43e22c717715f4cc2ae8
Fixed
7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af
Fixed
f4f699790590bd0896c48a71e9232a65198f92f0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74565.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74565.json"