What happened
A netfilter object can remain reachable after its expected lifecycle has ended, creating a stale-reference condition.
Affected versions
Linux kernel: 5.10–6.8.9 Fixed: Vendor dependent.
Why it matters
Kernel memory-safety issues can cross local privilege boundaries. Distribution-specific backports make package-level verification important.
Detection & mitigation
- Apply the kernel update provided by the operating-system vendor.
- Review container and local-user exposure.
- Use distribution advisories rather than upstream version alone to determine status.
Public PoC references
RepositoryAuthorFirst seenReference
netfilter-uaf-reproducerkernel-researchAug 31, 2026CandidateSource timeline
Initial record observedView source ↗
ExploitAlert record refreshed
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.