CVE-2026-98320

Source
https://cve.org/CVERecord?id=CVE-2026-98320
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98320.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98320
Downstream
Published
2026-10-06T08:46:14Z
Modified
2026-10-08T02:52:57Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
netfilter: flowtable: hold reference on ct until flow is released
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: hold reference on ct until flow is released

nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe semantics also allow to refer to the wrong conntrack from the flowtable datapath. Hold reference on ct until flow is released after rcu grace period.

Add rcu_barrier() on module exit path, to ensure pending flow entries are release before module goes away.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98320.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0ff90b6c20340e57616a51ae1a1bf18156d6638a
Fixed
93ff1594be1aad4da364462dd8db050ebcfda2de
Fixed
eed6997e8dc40593a539fcc722e7ed51b18db86c
Fixed
61c6688be282277c6e91ab286a7acd0ae8681ac6
Fixed
a43cd2b67b91e943273c913237a7a88c50cdcfbc
Fixed
8274cdc5f9c57e17ed77fc4ba76212536c840f25
Fixed
12c1ac230f4ca16e0017b62a963ab75e0b48074f
Fixed
d9e6175a3ee48209ee65f294fc567b4e16b29b74
Fixed
e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98320.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98320.json"