OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93288

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's netfilter component, specifically in the nfnetlink_log function, where the logger pointer is cleared without ensuring that all read-side critical sections have completed. This oversight could lead to use-after-free conditions, potentially allowing attackers to exploit concurrent packet processing. Organizations utilizing Linux kernel versions with this vulnerability should prioritize patching to mitigate risks associated with data corruption or system instability.

CVE
CVE-2026-93288
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state sashiko reports: "nfnl_log_net_exit() calls nf_log_unset(), which clears the logger pointer without an RCU grace period. Immediately after, ops_free_list() frees the per-net state while concurrent packets might still be executing nf_log_packet() under rcu_read_lock()." Clear the pointer via .pre_exit to make sure rcu readers have completed before pernet storage is free'd. The change in nf_log_syslog.c is only done for consistency: it doesn't use pernet data.