CVE-2026-93288

🟡 Monitoruj

Błąd w jądrze Linuxa pozwala na zwolnienie stanu pernet bez oczekiwania na zakończenie RCU, co może prowadzić do nieprzewidywalnych zachowań.

CVSS
7.8
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state sashiko reports: "nfnl_log_net_exit() calls nf_log_unset(), which clears the logger pointer without an RCU grace period. Immediately after, ops_free_list() frees the per-net state while concurrent packets might still be executing nf_log_packet() under rcu_read_lock()." Clear the pointer via .pre_exit to make sure rcu readers have completed before pernet storage is free'd. The change in nf_log_syslog.c is only done for consistency: it doesn't use pernet data.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2026-09-24 17:17:10 UTC
Ostatnia modyfikacja (NVD)2026-10-03 11:17:47 UTC
Referencje