CVE-2026-64150 PUBLISHED

netfilter: nft_inner: release local_lock before re-enabling softirqs

Assigner: Linux
Reserved: 19.07.2026 Published: 19.07.2026 Updated: 20.07.2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_inner: release local_lock before re-enabling softirqs

Quoting sashiko: In the error path, local_bh_enable() is called before local_unlock_nested_bh().

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from ba36fada9ab487634f61f92769c95bc148aa8f49 to df19b6af171695a1352314597c9a4311d48d5171 (excl.)
  • affected from ba36fada9ab487634f61f92769c95bc148aa8f49 to 6fecd39c6401134b58505bc4eb1adc8a0e2fe992 (excl.)
  • affected from ba36fada9ab487634f61f92769c95bc148aa8f49 to a6cb3ff979855f7f0ee9450a947fe8f96c2ba37a (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.34 to 6.18.* (incl.)
  • unaffected from 7.0.11 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References