Answer in brief
CVE-2026-97998 records a Unknown severity vulnerability in netfilter: nfnetlink_log: cope with concurrent instance destruction. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0597f2680d666a3bcf101ac0c771ba7e50016bbd <0234d7ca0317be0a623300e1693cd794bbfdf8af || >=0597f2680d666a3bcf101ac0c771ba7e50016bbd <1a7a8ac9a9f0ad0d410c901cb6f233833518844c || >=0597f2680d666a3bcf101ac0c771ba7e50016bbd <e2dd0f1f8c4e6334699ea6382e52f6da0c7e45eb || >=0597f2680d666a3bcf101ac0c771ba7e50016bbd <387d744fa7e499d2c3748a4e60e02ebb24e7fb16 | 0234d7ca0317be0a623300e1693cd794bbfdf8af, 1a7a8ac9a9f0ad0d410c901cb6f233833518844c, e2dd0f1f8c4e6334699ea6382e52f6da0c7e45eb, 387d744fa7e499d2c3748a4e60e02ebb24e7fb16 |
| Linux/Linuxgeneric | 2.6.14 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: cope with concurrent instance destruction Instances are refcounted. However, only memory release happens on the 1 -> 0 transition; the unlink from hashes can occur with any refcount. Uncooperative userspace can force a situation where a queue is pending for destruction from netlink event while a different socket with same portid processes an UNBIND request. With right timing, this will unhash the instance again: Oops: general protection fault, [..] Call Trace: <TASK> nfulnl_recv_config+0x31a/0xd50 nfnetlink_rcv_msg+0x7c2/0xeb0
Quoted source text, attributed separately from HOL analysis.