CVE-2026-45901 PUBLISHED

netfilter: nf_tables: revert commit_mutex usage in reset path

Assigner: Linux
Reserved: 13.05.2026 Published: 27.05.2026 Updated: 27.05.2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: revert commit_mutex usage in reset path

It causes circular lock dependency between commit_mutex, nfnl_subsys_ipset and nlk_cb_mutex when nft reset, ipset list, and iptables-nft with '-m set' rule run at the same time.

Previous patches made it safe to run individual reset handlers concurrently so commit_mutex is no longer required to prevent this.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 3cb03edb4de33fd04c4ea55f47397b96a8657c53 to ee3978b6a0dcd4215cb7cedcba705a12174786a7 (excl.)
  • affected from 3cb03edb4de33fd04c4ea55f47397b96a8657c53 to 7f261bb906bf527c4a6e2a646e2d5f3679f2a8bc (excl.)
  • Version fb1adb05ea87b6149e65a31e511756c4f470d0cd is affected
  • Version f123293db16dcd0cd81b246ae60e6362f0025d0a is affected
  • affected from 6.1.107 to 6.2 (excl.)
  • affected from 6.6.48 to 6.7 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.7 is affected
  • unaffected from 0 to 6.7 (excl.)
  • unaffected from 6.19.4 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References