CVE-2026-74565: Linux
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: make nft_object rhltable per table The nft_object rhltable is global, this allows for accessing objects that are being dismangled from lookup path by other existing netns. Given the nft_obj_destroy() releases the object inmediately, this might lead to use-after-free of these objects that are being released. Make the existing rhltable per table to address this issue to deal with with the nft_rcv_nl_event() path too. Update nft_obj_lookup() to take the table as non-const, otherwise, compiler complains when passing the objname_ht to rhltable_lookup().
Affected products
- Linux Linux: from 5.1, before 5.10.270 (fixed in 5.10.270); from 5.11, before 6.1.188 (fixed in 6.1.188); from 6.2, before 6.12.103 (fixed in 6.12.103); from 6.13, before 6.18.44 (fixed in 6.18.44); from 6.19, before 7.1.8 (fixed in 7.1.8)
Published 2026-08-15. Last modified 2026-09-14.