In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: move hardware offload step after building the chain blob… (CVE-2026-90062)
A high-severity vulnerability in the Linux kernel's netfilter nf_tables component has been resolved. The issue involved the order of operations during hardware offload of firewall rules, where the offload step occurred before the chain blob was fully built. This could lead to an inconsistent state between the offloaded ruleset in the network interface card and the software ruleset, potentially causing integrity issues. The fix moves the hardware offload step to after the chain blob allocation to prevent this inconsistency.
AI Analysis
Technical Summary
CVE-2026-90062 addresses a vulnerability in the Linux kernel's netfilter nf_tables subsystem. The flaw was due to performing the hardware offload step before the chain blob was allocated, which could result in a mismatch between the NIC offloaded ruleset and the software ruleset. The patch changes the sequence to allocate the chain blob before offloading the ruleset to hardware, reducing the risk of inconsistent firewall states.
Potential Impact
The vulnerability could cause the offloaded firewall ruleset on the network interface card to differ from the software ruleset, potentially leading to incorrect firewall behavior. The CVSS score of 7.1 indicates a high severity with impacts on integrity and availability, but no confidentiality impact. There are no known exploits in the wild.
Mitigation Recommendations
A fix is available that reorders the hardware offload step to occur after the chain blob allocation. Users should apply the official Linux kernel patch that addresses this issue. Since this is not a cloud service, remediation requires updating the affected Linux kernel versions once the patch is released.
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: move hardware offload step after building the chain blob… (CVE-2026-90062)
Description
A high-severity vulnerability in the Linux kernel's netfilter nf_tables component has been resolved. The issue involved the order of operations during hardware offload of firewall rules, where the offload step occurred before the chain blob was fully built. This could lead to an inconsistent state between the offloaded ruleset in the network interface card and the software ruleset, potentially causing integrity issues. The fix moves the hardware offload step to after the chain blob allocation to prevent this inconsistency.
CVSS v3.1
Score 7.1high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-90062 addresses a vulnerability in the Linux kernel's netfilter nf_tables subsystem. The flaw was due to performing the hardware offload step before the chain blob was allocated, which could result in a mismatch between the NIC offloaded ruleset and the software ruleset. The patch changes the sequence to allocate the chain blob before offloading the ruleset to hardware, reducing the risk of inconsistent firewall states.
Potential Impact
The vulnerability could cause the offloaded firewall ruleset on the network interface card to differ from the software ruleset, potentially leading to incorrect firewall behavior. The CVSS score of 7.1 indicates a high severity with impacts on integrity and availability, but no confidentiality impact. There are no known exploits in the wild.
Mitigation Recommendations
A fix is available that reorders the hardware offload step to occur after the chain blob allocation. Users should apply the official Linux kernel patch that addresses this issue. Since this is not a cloud service, remediation requires updating the affected Linux kernel versions once the patch is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-7p55-3fjg-254h
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-90062"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aade52855bf5e2cf5edc1d1
Added to database: 09/19/2026, 01:28:08 UTC
Last enriched: 09/19/2026, 01:55:11 UTC
Last updated: 09/19/2026, 02:01:34 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.