Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-64150

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-enabling softirqs Quoting sashiko: In the error path, local_bh_enable() is called before local_unlock_nested_bh().

View on NVD

Analysis

A critical vulnerability was found in the Linux kernel netfilter subsystem involving improper locking logic during network packet processing. Given its CVSS 9.8 rating and its location in the core networking stack, this could lead to remote exploitation or system compromise on Linux-based servers.

Relevant roles

LinuxCyberSecurityCloudDockerKubernetesBackend

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Probability of exploitation (next 30 days): 0.0017 (0.2%)
Percentile: 6.2%
EPSS: 2026-07-20

Technical description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-enabling softirqs Quoting sashiko: In the error path, local_bh_enable() is called before local_unlock_nested_bh().

Published: 7/19/2026, 4:17:56 PM
Last modified: 7/20/2026, 3:17:12 PM

References

HomeEventsBlogResourcesTeam