In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: add hook transactions for device deletions Restore the… (CVE-2026-63858)
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: add hook transactions for device deletions Restore the flag that indicates that the hook is going away, ie. NFT_HOOK_REMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase. The existing approach that moves the hook from the basechain/flowtable hook_list to transaction hook_list breaks netlink dump path readers of this RCU-protected list. It should be possible use an array for nft_trans_hook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place. Note that the nft_trans_chain_hooks() list contains a list of struct nft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nft_trans_hook for consistency. This patch also adapts the event notification path to deal with the list of hook transactions.
AI Analysis
Technical Summary
This vulnerability in the Linux kernel's netfilter nf_tables component was caused by the existing approach moving hooks from the basechain/flowtable hook_list to a transaction hook_list during device deletions. This behavior broke netlink dump path readers relying on the RCU-protected list. The fix restores the NFT_HOOK_REMOVE flag and adds a transaction object to track hook deletions without modifying the basechain/flowtable hook_list during preparation. Additionally, the event notification path was adapted to handle the new list of hook transactions, improving consistency and stability in hook management.
Potential Impact
The vulnerability could disrupt the integrity of netlink dump path readers accessing the RCU-protected hook list, potentially causing incorrect behavior or instability in netfilter operations. No direct exploitation details or impact on confidentiality, integrity, or availability are provided. Known exploits in the wild are not reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to address this vulnerability. Users should apply the official kernel updates that include this patch. Since no cloud service is involved, remediation depends on deploying the updated kernel version. Patch status is not explicitly confirmed in the provided data; users should consult the Linux kernel vendor advisory or distribution security updates for the official fix and deployment instructions.
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: add hook transactions for device deletions Restore the… (CVE-2026-63858)
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: add hook transactions for device deletions Restore the flag that indicates that the hook is going away, ie. NFT_HOOK_REMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase. The existing approach that moves the hook from the basechain/flowtable hook_list to transaction hook_list breaks netlink dump path readers of this RCU-protected list. It should be possible use an array for nft_trans_hook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place. Note that the nft_trans_chain_hooks() list contains a list of struct nft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nft_trans_hook for consistency. This patch also adapts the event notification path to deal with the list of hook transactions.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in the Linux kernel's netfilter nf_tables component was caused by the existing approach moving hooks from the basechain/flowtable hook_list to a transaction hook_list during device deletions. This behavior broke netlink dump path readers relying on the RCU-protected list. The fix restores the NFT_HOOK_REMOVE flag and adds a transaction object to track hook deletions without modifying the basechain/flowtable hook_list during preparation. Additionally, the event notification path was adapted to handle the new list of hook transactions, improving consistency and stability in hook management.
Potential Impact
The vulnerability could disrupt the integrity of netlink dump path readers accessing the RCU-protected hook list, potentially causing incorrect behavior or instability in netfilter operations. No direct exploitation details or impact on confidentiality, integrity, or availability are provided. Known exploits in the wild are not reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to address this vulnerability. Users should apply the official kernel updates that include this patch. Since no cloud service is involved, remediation depends on deploying the updated kernel version. Patch status is not explicitly confirmed in the provided data; users should consult the Linux kernel vendor advisory or distribution security updates for the official fix and deployment instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-w348-qxhm-w5rx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63858"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a5d27ac2a4a8d5989130654
Added to database: 07/19/2026, 19:38:20 UTC
Last enriched: 07/19/2026, 20:14:59 UTC
Last updated: 09/03/2026, 10:52:10 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.