---
id: CVE-2026-74565
title: 'netfilter: nf_tables: make nft_object rhltable per table'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netfilter: nf_tables: make nft_object rhltable per table

  The nft_object rhltable is global, this allows for accessing objects
  that are being dismangled from lookup pat…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 <
    4b549d32d34ee765527e63726bb1af984876e776
  - >-
    Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 <
    523c881661dde67efb44fce38c8eed50a72a57c1
  - >-
    Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 <
    1948e4f85b855618b5b9a27265f98d816f4cb7cb
  - >-
    Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 <
    63ba12b664a2cd3220ed43e22c717715f4cc2ae8
  - >-
    Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 <
    7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af
  - >-
    Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 <
    f4f699790590bd0896c48a71e9232a65198f92f0
  - Linux 5.1
published: '2026-08-15'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T11:58:48.270Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-74565'
references:
  - url: 'https://git.kernel.org/stable/c/4b549d32d34ee765527e63726bb1af984876e776'
  - url: 'https://git.kernel.org/stable/c/523c881661dde67efb44fce38c8eed50a72a57c1'
  - url: 'https://git.kernel.org/stable/c/1948e4f85b855618b5b9a27265f98d816f4cb7cb'
  - url: 'https://git.kernel.org/stable/c/63ba12b664a2cd3220ed43e22c717715f4cc2ae8'
  - url: 'https://git.kernel.org/stable/c/7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af'
  - url: 'https://git.kernel.org/stable/c/f4f699790590bd0896c48a71e9232a65198f92f0'
tags:
  - cve.org
epss: 0.00171
epssPercentile: 0.05664
ingestedAt: '2026-09-14T15:23:07.456Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: make nft_object rhltable per table

The nft_object rhltable is global, this allows for accessing objects
that are being dismangled from lookup path by other existing netns.
Given the nft_obj_destroy() releases the object inmediately, this might
lead to use-after-free of these objects that are being released.
Make the existing rhltable per table to address this issue to deal with
with the nft_rcv_nl_event() path too.

Update nft_obj_lookup() to take the table as non-const, otherwise,
compiler complains when passing the objname_ht to rhltable_lookup().

## Affected

- `Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 < 4b549d32d34ee765527e63726bb1af984876e776`
- `Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 < 523c881661dde67efb44fce38c8eed50a72a57c1`
- `Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 < 1948e4f85b855618b5b9a27265f98d816f4cb7cb`
- `Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 < 63ba12b664a2cd3220ed43e22c717715f4cc2ae8`
- `Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 < 7d4789b58761d9d48d9b5f5e7e0a510c3bbfb3af`
- `Linux >= 4d44175aa5bb5f68772b1eb0306554812294ca52 < f4f699790590bd0896c48a71e9232a65198f92f0`
- `Linux 5.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
