Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required.
nft_map_catchall_activate() is called from the abort path to re-activate catchall map elements that were deactivated during a failed transaction. It should skip elements that are already active (they don’t need re-activation) and process elements that are inactive (they need to be restored). Instead, the current code does the opposite: it skips inactive elements and processes active ones.
Compare the non-catchall activate callback, which is correct:
nft_mapelem_activate(): if (nft_set_elem_active(ext, iter->genmask)) return 0; /* skip active, process inactive */
With the buggy catchall version:
nft_map_catchall_activate(): if (!nft_set_elem_active(ext, genmask)) continue; /* skip inactive, process active */
The consequence is that when a DELSET operation is aborted, nft_setelem_data_activate() is never called for the catchall element. For NFT_GOTO verdict elements, this means nft_data_hold() is never called to restore the chain->use reference count. Each abort cycle permanently decrements chain->use. Once chain->use reaches zero, DELCHAIN succeeds and frees the chain while catchall verdict elements still reference it, resulting in a use-after-free.
This is exploitable for local privilege escalation from an unprivileged user via user namespaces + nftables on distributions that enable CONFIG_USER_NS and CONFIG_NF_TABLES.
Fix by removing the negation so the check matches nft_mapelem_activate(): skip active elements, process inactive ones.
Details
- Affected product:
- AlmaLinux 9.2 ESU , TuxCare 9.6 ESU , Ubuntu 20.04 ELS
- Affected packages:
- linux-meta @ 5.4.0 (+3 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| AlmaLinux 10 | Released |
37 kernels
|
| AlmaLinux 9 | Released |
79 kernels
|
| AlmaLinux 9.2 ESU | Released |
24 kernels
|
| AlmaLinux 9.6 ESU | Released |
3 kernels
|
| Amazon Linux 2023 | Released |
46 kernels
|
| Debian 12 | Released |
33 kernels
|
| Debian 13 | Released |
1 kernel
|
| Oracle Linux 10 | Released |
35 kernels
|
| Oracle Linux 8 UEK 7 | In Progress | — |
| Oracle Linux 9 | Released |
82 kernels
|
| Oracle Linux 9 UEK 7 | In Progress | — |
| Proxmox VE 7 5.15 | Released |
10 kernels
|
| RHEL 10 | Released |
37 kernels
|
| RHEL 9 | Released |
80 kernels
|
| Rocky Linux 10 | Released |
27 kernels
|
| Rocky Linux 9 | Released |
65 kernels
|
| Ubuntu 20.04 HWE AWS | Released |
31 kernels
|
| Ubuntu 20.04 HWE Azure | Released |
28 kernels
|
| Ubuntu 22.04 | Released |
53 kernels
|
| Ubuntu 22.04 AWS | Released |
49 kernels
|
| Ubuntu 22.04 Azure | Released |
44 kernels
|
| Ubuntu 24.04 | Released |
40 kernels
|
| Ubuntu 24.04 AWS | Ready For Release | — |