« Volver al listado

CVE-2026-63858

Estado: Pendiente de análisisAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: add hook transactions for device deletions

Restore the flag that indicates that the hook is going away, ie. NFT_HOOK_REMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase.

The existing approach that moves the hook from the basechain/flowtable hook_list to transaction hook_list breaks netlink dump path readers of this RCU-protected list.

It should be possible use an array for nft_trans_hook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place.

Leer descripción completaMostrar menos

Note that the nft_trans_chain_hooks() list contains a list of struct nft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nft_trans_hook for consistency.

This patch also adapts the event notification path to deal with the list of hook transactions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vuln. local sin interacción (AV:L, PR:L, UI:N) en kernel Linux con impacto total (C:H, I:H, A:H); permite escalar privilegios. La manipulación de hooks netfilter facilita ejecución de código kernel o DoS.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-63858",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b6d9014a3335194590abdd2a2471ef5147a67645",
              "lessThan": "4e69bfb32b2db323d9205fdb30e284481b37817c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b6d9014a3335194590abdd2a2471ef5147a67645",
              "lessThan": "10f79dbd7719d1da9f5884d13060322d8729f091",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7a248f9c74f9f62799718c12efd9e9e391d60b6f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f275989ad04159dbfc62cefb65ba9c5ba1d7c34f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "62d91062058b42bf70b2c3446aec397bb0ce15ee",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "99180dec5ae582227219d1fdd0dd5ccf53ec7491",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.122",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.47",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.17.15",
              "lessThan": "5.18",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.18.4",
              "lessThan": "5.19",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "include/net/netfilter/nf_tables.h",
            "net/netfilter/nf_tables_api.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.0.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "include/net/netfilter/nf_tables.h",
            "net/netfilter/nf_tables_api.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-19T15:16:52.643",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/10f79dbd7719d1da9f5884d13060322d8729f091",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4e69bfb32b2db323d9205fdb30e284481b37817c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: add hook transactions for device deletions\n\nRestore the flag that indicates that the hook is going away, ie.\nNFT_HOOK_REMOVE, but add a new transaction object to track deletion\nof hooks without altering the basechain/flowtable hook_list during\nthe preparation phase.\n\nThe existing approach that moves the hook from the basechain/flowtable\nhook_list to transaction hook_list breaks netlink dump path readers\nof this RCU-protected list.\n\nIt should be possible use an array for nft_trans_hook to store the\ndeleted hooks to compact the representation but I am not expecting\nmany hook object, specially now that wildcard support for devices\nis in place.\n\nNote that the nft_trans_chain_hooks() list contains a list of struct\nnft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while\nthis list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE.\nNote that new commands can be updated to use nft_trans_hook for\nconsistency.\n\nThis patch also adapts the event notification path to deal with the list\nof hook transactions."
    }
  ],
  "lastModified": "2026-07-27T17:44:23.777",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}