{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-56655",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-12-27T15:00:39.841Z",
        "datePublished": "2024-12-27T15:06:19.033Z",
        "dateUpdated": "2026-08-05T11:45:53.066Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:45:53.066Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: do not defer rule destruction via call_rcu\n\nnf_tables_chain_destroy can sleep, it can't be used from call_rcu\ncallbacks.\n\nMoreover, nf_tables_rule_release() is only safe for error unwinding,\nwhile transaction mutex is held and the to-be-desroyed rule was not\nexposed to either dataplane or dumps, as it deactives+frees without\nthe required synchronize_rcu() in-between.\n\nnft_rule_expr_deactivate() callbacks will change ->use counters\nof other chains/sets, see e.g. nft_lookup .deactivate callback, these\nmust be serialized via transaction mutex.\n\nAlso add a few lockdep asserts to make this more explicit.\n\nCalling synchronize_rcu() isn't ideal, but fixing this without is hard\nand way more intrusive.  As-is, we can get:\n\nWARNING: .. net/netfilter/nf_tables_api.c:5515 nft_set_destroy+0x..\nWorkqueue: events nf_tables_trans_destroy_work\nRIP: 0010:nft_set_destroy+0x3fe/0x5c0\nCall Trace:\n <TASK>\n nf_tables_trans_destroy_work+0x6b7/0xad0\n process_one_work+0x64a/0xce0\n worker_thread+0x613/0x10d0\n\nIn case the synchronize_rcu becomes an issue, we can explore alternatives.\n\nOne way would be to allocate nft_trans_rule objects + one nft_trans_chain\nobject, deactivate the rules + the chain and then defer the freeing to the\nnft destroy workqueue.  We'd still need to keep the synchronize_rcu path as\na fallback to handle -ENOMEM corner cases though."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable path is driven entirely from local interfaces — nfnetlink/NETLINK_NETFILTER to build a netdev-family basechain with rules, and RTNETLINK to unregister the device that fires the NETDEV_UNREGISTER notifier. No remote peer can drive basechain release.\nAC:L - The attacker owns both sides: it creates the netns, the device, and the ruleset, chooses when to delete the device, and issues concurrent nftables transactions that race the unserialized softirq callback, repeating indefinitely; the sleeping-in-atomic path (`cancel_delayed_work_sync`/`mutex_lock` from an RCU softirq callback) is deterministic and needs no race at all.\nPR:L - nfnetlink only requires `netlink_net_capable(skb, CAP_NET_ADMIN)`, evaluated against the network namespace's user_ns, so an unprivileged local user obtains everything needed via `unshare -Urn` — including creating and deleting the dummy/veth device that triggers the notifier.\nUI:N - The attacker performs every step itself — ruleset setup, device removal, and the concurrent transactions; no victim action or pre-existing administrator configuration is needed.\nS:U - Corruption is confined to nf_tables kernel objects within the same kernel security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - Unserialized `nft_use_dec()` on `set->use`/`chain->use`/`obj->use` races the commit-mutex-protected control plane, so counters underflow and still-referenced sets/chains are freed, yielding a use-after-free whose reclaimed contents the attacker can shape and read back via ruleset dumps.\nI:H - The softirq callback performs `list_del_rcu()` on `table->sets`/`table->chains` and `rhltable_remove()` on `chains_ht` concurrently with control-plane insertions/removals, giving list and rhashtable corruption on top of the UAF — both standard springboards to controlled kernel writes and control-flow hijack.\nA:H - Sleeping functions (`cancel_delayed_work_sync`, `mutex_lock` via `nf_ct_netns_put`, `nf_tables_chain_destroy`) invoked from an RCU softirq callback produce \"sleeping function called from invalid context\" BUGs and scheduler corruption, and the refcount/list corruption reliably ends in WARNs, oopses, and panics."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "include/net/netfilter/nf_tables.h",
                        "net/netfilter/nf_tables_api.c"
                    ],
                    "versions": [
                        {
                            "version": "9eee6097ffb26cdd2adb988c0d378fa0d650c737",
                            "lessThan": "5146c27b2780aac59876a887a5f4e793b8949862",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "558f503f707f481bbf40efa74a938b8021df841d",
                            "lessThan": "2991dc357a28b61c13ed1f7b59e9251e2b4562fb",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a394c160d57f4b083bd904a22802f6fb7f5b3cea",
                            "lessThan": "b8d8f53e1858178882b881b8c09f94ef0e83bf76",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e6c32a64d61184c2bdf89442b3d31ef530afba34",
                            "lessThan": "b0f013bebf94fe7ae75e5a53be2f2bd1cc1841e3",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "bfd05c68e4c6320304e9f371ffa356b6e4b9cc53",
                            "lessThan": "27f0574253f6c24c8ee4e3f0a685b75ed3a256ed",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "c03d278fdf35e73dd0ec543b9b556876b9d9a8dc",
                            "lessThan": "7cf0bd232b565d9852cb25fd094f77254773e048",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "c03d278fdf35e73dd0ec543b9b556876b9d9a8dc",
                            "lessThan": "b04df3da1b5c6f6dc7cdccc37941740c078c4043",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "cb401e5799e0acacb405f2128097e9c4ccf82f8a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6.6.61",
                            "lessThan": "6.6.67",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11.8",
                            "lessThan": "6.12",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "include/net/netfilter/nf_tables.h",
                        "net/netfilter/nf_tables_api.c"
                    ],
                    "versions": [
                        {
                            "version": "6.12",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.12",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.67",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.6",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6.61",
                                    "versionEndExcluding": "6.6.67"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.12.6"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12",
                                    "versionEndExcluding": "6.13"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.11.8"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/5146c27b2780aac59876a887a5f4e793b8949862"
                },
                {
                    "url": "https://git.kernel.org/stable/c/2991dc357a28b61c13ed1f7b59e9251e2b4562fb"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b8d8f53e1858178882b881b8c09f94ef0e83bf76"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b0f013bebf94fe7ae75e5a53be2f2bd1cc1841e3"
                },
                {
                    "url": "https://git.kernel.org/stable/c/27f0574253f6c24c8ee4e3f0a685b75ed3a256ed"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7cf0bd232b565d9852cb25fd094f77254773e048"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b04df3da1b5c6f6dc7cdccc37941740c078c4043"
                }
            ],
            "title": "netfilter: nf_tables: do not defer rule destruction via call_rcu",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}