CVE-2026-90062 PUBLISHED

netfilter: nf_tables: move hardware offload step after building the chain blob

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: move hardware offload step after building the chain blob

Allocate the chain blob before the ruleset offload to reduce chances of entering an inconsistent state where the offloaded ruleset in the nic and the software ruleset differ.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from c9626a2cbdb20e26587b3fad99960520a023432b to 923f824f30faebc5560c3061a595063cecdbdbb8 (excl.)
  • affected from c9626a2cbdb20e26587b3fad99960520a023432b to 6e7ad6e69be4751ab2476042c70c600bdaa8d4f2 (excl.)
  • affected from c9626a2cbdb20e26587b3fad99960520a023432b to 309acbab74e46114246bf4346c9b60b3d8cb4fcd (excl.)
  • affected from c9626a2cbdb20e26587b3fad99960520a023432b to 79eafe22ab0a650996da2b3e5d94a12c3e16f3aa (excl.)
  • affected from c9626a2cbdb20e26587b3fad99960520a023432b to 52febaf1d311d6ede312b2ec7692a309714f9554 (excl.)
  • affected from c9626a2cbdb20e26587b3fad99960520a023432b to d5497644329d3a01e951aba76561bbd883ff6b0c (excl.)
  • affected from c9626a2cbdb20e26587b3fad99960520a023432b to 6a7d3b074cfbb64513f5f92d60ab1b216ae98076 (excl.)
  • affected from c9626a2cbdb20e26587b3fad99960520a023432b to b1881d362e1924b66f6016c3efd28807032b41bf (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.3 is affected
  • unaffected from 0 to 5.3 (excl.)
  • unaffected from 5.10.270 to 5.10.* (incl.)
  • unaffected from 5.15.221 to 5.15.* (incl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References