CVE-2026-64150
A critical flaw in the Linux kernel’s netfilter nft_inner component could allow attackers to crash the system or potentially gain control. The issue stems from improper handling of local locks and softirqs during error paths. The vulnerability has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users running affected versions of the netfilter nft_inner component.
Real-world impact
An attacker could cause a denial of service, steal sensitive data, or modify system files by exploiting the improper lock handling.
Why this severity
The CVSS score of 9.8 reflects that the flaw is network‑exploitable without authentication and can lead to full compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for netfilter: nft_inner: release local_lock before re-enabling softirqs.
NVD description indicates the vulnerability has been resolved.
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.