Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-64150Critical security flaw in Linux Kernel Netfilter

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-enabling softirqs Quoting sashiko: In the error path, local_bh_enable() is called before local_unlock_nested_bh().

View on NVD

Analysis

A critical vulnerability was found in the Linux kernel netfilter subsystem involving improper locking logic during network packet processing. Given its CVSS 9.8 rating and its location in the core networking stack, this could lead to remote exploitation or system compromise on Linux-based servers.

Relevant roles

LinuxCyberSecurityCloudDockerKubernetesBackend

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): NVD-CWE-noinfo

EPSS

Probability of exploitation (next 30 days): 0.0044 (0.4%)
Percentile: 36.8%
EPSS: 2026-08-17

Affects

linux:linux_kernel

Technical description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-enabling softirqs Quoting sashiko: In the error path, local_bh_enable() is called before local_unlock_nested_bh().

Published: 7/19/2026, 4:17:56 PM
Last modified: 8/17/2026, 5:11:52 PM

References

HomeEventsBlogResourcesCoursesTeam