« Volver al listado

CVE-2026-90237

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_ct: move custom expectation support to helper

Originally, the ct expectation support called nf_ct_helper_ext_add() for confirmed conntracks, which is invalid, triggering a splat. This was fixed by commit 1710eb913bdc ("netfilter: nft_ct: skip expectations for confirmed conntrack") which restricted it to unconfirmed conntracks.

However, early insertion of expectations into the expectations list when the conntrack is unconfirmed leads to stale entries pointing to the wrong hlist_head through .pprev due to ct extension reallocation.

Leer descripción completaMostrar menos

Commit 7c9664351980 ("netfilter: move nat hlist_head to nf_conn") moved the nat hlist_head to nf_conn for this reason:

I'd rather not increase the size of the struct nf_conn for this feature has very limited scope: only one expectation can be created at a time given expect_clash() will make nf_ct_expect_related() reports EBUSY. For this reason, relax nf_ct_expect_related() not to drop packets in case expectation creation fails, therefore, expectation creation becomes best effort.

To address this issue, add an internal ct helper and attach it to the conntrack entry to streamline the custom ct expectation support with existing ct helpers.

Expose a new nf_conntrack_helper_release() function to release the internal helper that is allocated and attached to the conntrack entry to create the custom expectations. The nft_ct module removal always waits for rcu grace period, then the NULL helper callback is observed after this.

This patch also restricts the creation of expectations to different helpers other than this custom helper that is created for this type of expectations.

Detalles técnicos trazas, registros y código del informe original
     1. ...
     2. When reallocation of extension area occurs we need to fixup the
        bysource hash head via hlist_replace_rcu.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Escalada local de privilegios en kernel Linux (AV:L/PR:L) mediante corrupción de memoria en netfilter. Causa potencial DoS o denegación de acceso a recursos por entradas stale en hlist.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90237",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "857b46027d6f91150797295752581b7155b9d0e1",
              "lessThan": "af3fe52fd108fd38235e4813df62442ed0f1d8ff",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "857b46027d6f91150797295752581b7155b9d0e1",
              "lessThan": "3679da4ad8be84cddaf40bc307fef1fe13e051ff",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "include/net/netfilter/nf_conntrack_helper.h",
            "net/netfilter/nf_conntrack_helper.c",
            "net/netfilter/nft_ct.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/net/netfilter/nf_conntrack_helper.h",
            "net/netfilter/nf_conntrack_helper.c",
            "net/netfilter/nft_ct.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:19.640",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3679da4ad8be84cddaf40bc307fef1fe13e051ff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/af3fe52fd108fd38235e4813df62442ed0f1d8ff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: move custom expectation support to helper\n\nOriginally, the ct expectation support called nf_ct_helper_ext_add() for\nconfirmed conntracks, which is invalid, triggering a splat. This was\nfixed by commit 1710eb913bdc (\"netfilter: nft_ct: skip expectations for\nconfirmed conntrack\") which restricted it to unconfirmed conntracks.\n\nHowever, early insertion of expectations into the expectations list when\nthe conntrack is unconfirmed leads to stale entries pointing to the\nwrong hlist_head through .pprev due to ct extension reallocation.\n\nCommit 7c9664351980 (\"netfilter: move nat hlist_head to nf_conn\") moved\nthe nat hlist_head to nf_conn for this reason:\n\n     1. ...\n     2. When reallocation of extension area occurs we need to fixup the\n        bysource hash head via hlist_replace_rcu.\n\nI'd rather not increase the size of the struct nf_conn for this feature\nhas very limited scope: only one expectation can be created at a time\ngiven expect_clash() will make nf_ct_expect_related() reports EBUSY.\nFor this reason, relax nf_ct_expect_related() not to drop packets in\ncase expectation creation fails, therefore, expectation creation becomes\nbest effort.\n\nTo address this issue, add an internal ct helper and attach it to the\nconntrack entry to streamline the custom ct expectation support with\nexisting ct helpers.\n\nExpose a new nf_conntrack_helper_release() function to release the\ninternal helper that is allocated and attached to the conntrack entry to\ncreate the custom expectations. The nft_ct module removal always waits\nfor rcu grace period, then the NULL helper callback is observed after\nthis.\n\nThis patch also restricts the creation of expectations to different\nhelpers other than this custom helper that is created for this type of\nexpectations."
    }
  ],
  "lastModified": "2026-09-18T18:17:50.027",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}