---
id: CVE-2026-90062
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netfilter: nf_tables: move hardware offload step after building the chain blob

  Allocate the chain blob before the ruleset offload to reduce chances of
  entering an inco…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  netfilter: nf_tables: move hardware offload step after building the chain blob

  Allocate the chain blob before the ruleset offload to reduce chances of
  entering an inco…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= c9626a2cbdb20e26587b3fad99960520a023432b <
    923f824f30faebc5560c3061a595063cecdbdbb8
  - >-
    Linux >= c9626a2cbdb20e26587b3fad99960520a023432b <
    6e7ad6e69be4751ab2476042c70c600bdaa8d4f2
  - >-
    Linux >= c9626a2cbdb20e26587b3fad99960520a023432b <
    309acbab74e46114246bf4346c9b60b3d8cb4fcd
  - >-
    Linux >= c9626a2cbdb20e26587b3fad99960520a023432b <
    79eafe22ab0a650996da2b3e5d94a12c3e16f3aa
  - >-
    Linux >= c9626a2cbdb20e26587b3fad99960520a023432b <
    52febaf1d311d6ede312b2ec7692a309714f9554
  - >-
    Linux >= c9626a2cbdb20e26587b3fad99960520a023432b <
    d5497644329d3a01e951aba76561bbd883ff6b0c
  - >-
    Linux >= c9626a2cbdb20e26587b3fad99960520a023432b <
    6a7d3b074cfbb64513f5f92d60ab1b216ae98076
  - >-
    Linux >= c9626a2cbdb20e26587b3fad99960520a023432b <
    b1881d362e1924b66f6016c3efd28807032b41bf
  - Linux 5.3
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:40.363'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90062'
references:
  - url: 'https://git.kernel.org/stable/c/309acbab74e46114246bf4346c9b60b3d8cb4fcd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/52febaf1d311d6ede312b2ec7692a309714f9554'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6a7d3b074cfbb64513f5f92d60ab1b216ae98076'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6e7ad6e69be4751ab2476042c70c600bdaa8d4f2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/79eafe22ab0a650996da2b3e5d94a12c3e16f3aa'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/923f824f30faebc5560c3061a595063cecdbdbb8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b1881d362e1924b66f6016c3efd28807032b41bf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d5497644329d3a01e951aba76561bbd883ff6b0c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.0016
epssPercentile: 0.05614
ingestedAt: '2026-09-17T16:21:47.901Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: move hardware offload step after building the chain blob

Allocate the chain blob before the ruleset offload to reduce chances of
entering an inconsistent state where the offloaded ruleset in the nic
and the software ruleset differ.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
