<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:12:48 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-42109 — netfilter: nf_tables: unconditionally flush pending work before notifier</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-42109</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_tables: unconditionally flush pending work before notifier&lt;/p&gt;
&lt;p&gt;syzbot reports:&lt;/p&gt;
&lt;p&gt;KASAN: slab-uaf in nft_ctx_update include/net/netfilter/nf_tables.h:1831
KASAN: slab-uaf in nft_commit_release net/netfilter/nf_tables_api.c:9530
KASAN: slab-uaf int nf_tables_trans_destroy_work+0x152b/0x1750 net/netfilter/nf_tables_api.c:9597
Read of size 2 at addr ffff88802b0051c4 by task kworker/1:1/45
[..]
Workqueue: events nf_tables_trans_destroy_work
Call Trace:
 nft_ctx_update include/net/netfilter/nf_tables.h:1831 [inline]
 nft_commit_release net/netfilter/nf_tables_api.c:9530 [inline]
 nf_tables_trans_destroy_work+0x152b/0x1750 net/netfilter/nf_tables_api.c:9597&lt;/p&gt;
&lt;p&gt;Problem is that the notifier does a conditional flush, but its possible
that the table-to-be-removed is still referenced by transactions being
processed by the worker, so we need to flush unconditionally.&lt;/p&gt;
&lt;p&gt;We could make the flush_work depend on whether we found a table to delete
in nf-next to avoid the flush for most cases.&lt;/p&gt;
&lt;p&gt;AFAICS this problem is only exposed in nf-next, with
commit e169285f8c56 (&amp;#34;netfilter: nf_tables: do not store nft_ctx in transaction objects&amp;#34;),
with this commit applied there is an unconditional fetch of
table-&amp;gt;family which is whats triggering the above splat.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_tables: unconditionally flush pending work before notifier&lt;/p&gt;
&lt;p&gt;syzbot reports:&lt;/p&gt;
&lt;p&gt;KASAN: slab-uaf in nft_ctx_update include/net/netfilter/nf_tables.h:1831
KASAN: slab-uaf in nft_commit_release net/netfilter/nf_tables_api.c:9530
KASAN: slab-uaf int nf_tables_trans_destroy_work+0x152b/0x1750 net/netfilter/nf_tables_api.c:9597
Read of size 2 at addr ffff88802b0051c4 by task kworker/1:1/45
[..]
Workqueue: events nf_tables_trans_destroy_work
Call Trace:
 nft_ctx_update include/net/netfilter/nf_tables.h:1831 [inline]
 nft_commit_release net/netfilter/nf_tables_api.c:9530 [inline]
 nf_tables_trans_destroy_work+0x152b/0x1750 net/netfilter/nf_tables_api.c:9597&lt;/p&gt;
&lt;p&gt;Problem is that the notifier does a conditional flush, but its possible
that the table-to-be-removed is still referenced by transactions being
processed by the worker, so we need to flush unconditionally.&lt;/p&gt;
&lt;p&gt;We could make the flush_work depend on whether we found a table to delete
in nf-next to avoid the flush for most cases.&lt;/p&gt;
&lt;p&gt;AFAICS this problem is only exposed in nf-next, with
commit e169285f8c56 (&amp;#34;netfilter: nf_tables: do not store nft_ctx in transaction objects&amp;#34;),
with this commit applied there is an unconditional fetch of
table-&amp;gt;family which is whats triggering the above splat.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-42109</guid>
    </item>
  </channel>
</rss>
