CVE-2026-74660: netfilter: ebt_nflog: pin the NFLOG backend
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026082227-CVE-2026-74660-15ff@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: netfilter: ebt_nflog: pin the NFLOG backend nf_log_unregister() runs after the per-net teardown so its final RCU grace period also drains readers that obtained the logger from a per-net binding. However, ebt_nflog passes an explicit ULOG log type to nf_log_packet() without holding a reference on the selected logger module, unlike the xt_NFLOG and nft_log frontends. An ebtables nflog rule can therefore remain callable while nfnetlink_log is unloaded. The resulting interleaving is: CPU 0 CPU 1 nfnetlink_log_fini() unregister_pernet_subsys() kfree(nfnl_log_pernet(net)) ebt_nflog_tg() nf_log_packet() nfulnl_log_packet() instance_lookup_get_rcu() The global ULOG logger is still registered at this point, so CPU 1 dereferences the per-net state after CPU 0 has freed it. KASAN reported: BUG: KASAN: slab-use-after-free in instance_lookup_get_rcu Read of size 8 at addr ff110001052e6210 by task poc/92 Call Trace: instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log] nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log] nf_log_packet+0x204/0x300 ebt_nflog_tg+0x351/0x550 ebt_do_table+0xedf/0x22b0 Allocated by task 90: __kmalloc_noprof+0x186/0x470 ops_init+0x6d/0x420 register_pernet_operations+0x2f6/0x670 register_pernet_subsys+0x23/0x40 Freed by task 93: kfree+0x131/0x3c0 ops_undo_list+0x3e3/0x700 unregister_pernet_operations+0x232/0x490 unregister_pernet_subsys+0x1c/0x30 nfnetlink_log_fini+0x34/0x450 [nfnetlink_log] Acquire the ULOG logger module reference when an ebt_nflog rule is validated and release it when the rule is destroyed. Request the NFLOG backend for legacy callers when needed, matching xt_NFLOG. This prevents module teardown until all ebt_nflog rules have stopped using the logger. The Linux kernel CVE team has assigned CVE-2026-74660 to this issue. Affected and fixed versions =========================== Issue introduced in 4.12 with commit c83fa19603bdaeef17b815713dbbe3230c8a34ee and fixed in 5.10.265 with commit 3bcce49d617c593c7606083bfdb464a1761fa68d Issue introduced in 4.12 with commit c83fa19603bdaeef17b815713dbbe3230c8a34ee and fixed in 5.15.216 with commit 394d7939c6b2b9e6bea0844c89efb5913168d898 Issue introduced in 4.12 with commit c83fa19603bdaeef17b815713dbbe3230c8a34ee and fixed in 6.1.183 with commit 2cac4294f184c9bc19ff82552c62b80498694c39 Issue introduced in 4.12 with commit c83fa19603bdaeef17b815713dbbe3230c8a34ee and fixed in 6.6.152 with commit 9d8a94b48b393885e7f876c8ef68ed4da5012078 Issue introduced in 4.12 with commit c83fa19603bdaeef17b815713dbbe3230c8a34ee and fixed in 6.12.104 with commit 6809379a860b9fccbb5435bf08343f6d081ac68d Issue introduced in 4.12 with commit c83fa19603bdaeef17b815713dbbe3230c8a34ee and fixed in 6.18.45 with commit 47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb Issue introduced in 4.12 with commit c83fa19603bdaeef17b815713dbbe3230c8a34ee and fixed in 7.1.9 with commit e2ab7e878bdbe80104c879c31fd2d82a476703b8 Issue introduced in 4.12 with commit c83fa19603bdaeef17b815713dbbe3230c8a34ee and fixed in 7.2 with commit 30825970339c107bacaf7f61af90fcdb1f597ca1 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74660 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/bridge/netfilter/ebt_nflog.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/3bcce49d617c593c7606083bfdb464a1761fa68d https://git.kernel.org/stable/c/394d7939c6b2b9e6bea0844c89efb5913168d898 https://git.kernel.org/stable/c/2cac4294f184c9bc19ff82552c62b80498694c39 https://git.kernel.org/stable/c/9d8a94b48b393885e7f876c8ef68ed4da5012078 https://git.kernel.org/stable/c/6809379a860b9fccbb5435bf08343f6d081ac68d https://git.kernel.org/stable/c/47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb https://git.kernel.org/stable/c/e2ab7e878bdbe80104c879c31fd2d82a476703b8 https://git.kernel.org/stable/c/30825970339c107bacaf7f61af90fcdb1f597ca1