Linux Kernel Netfilter nf_tables Garbage Collection Vulnerability

Vulnerability

A vulnerability in the Linux kernel's netfilter component, specifically within the nf_tables backend, has been addressed. This issue involved the garbage collection (GC) process, where elements were improperly managed, leading to potential visibility during lookups. The vulnerability arose because the asynchronous GC could enqueue transaction work that might be aborted and retried, causing inconsistencies. Additionally, certain backend types did not properly synchronize GC operations, leaving elements in a state that could interfere with normal processing.

Impact

Exploitation of this vulnerability could lead to improper management of set elements in the garbage collection process, potentially allowing for elements to remain visible during lookups when they should have been deactivated.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.