{"id":"CVE-2026-90062","summary":"netfilter: nf_tables: move hardware offload step after building the chain blob","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: move hardware offload step after building the chain blob\n\nAllocate the chain blob before the ruleset offload to reduce chances of\nentering an inconsistent state where the offloaded ruleset in the nic\nand the software ruleset differ.","modified":"2026-09-19T03:47:30.979219968Z","published":"2026-09-17T16:05:45.853Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90062.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/309acbab74e46114246bf4346c9b60b3d8cb4fcd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/52febaf1d311d6ede312b2ec7692a309714f9554"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6a7d3b074cfbb64513f5f92d60ab1b216ae98076"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6e7ad6e69be4751ab2476042c70c600bdaa8d4f2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/79eafe22ab0a650996da2b3e5d94a12c3e16f3aa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/923f824f30faebc5560c3061a595063cecdbdbb8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b1881d362e1924b66f6016c3efd28807032b41bf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d5497644329d3a01e951aba76561bbd883ff6b0c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90062.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90062"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"c9626a2cbdb20e26587b3fad99960520a023432b"},{"fixed":"923f824f30faebc5560c3061a595063cecdbdbb8"},{"fixed":"6e7ad6e69be4751ab2476042c70c600bdaa8d4f2"},{"fixed":"309acbab74e46114246bf4346c9b60b3d8cb4fcd"},{"fixed":"79eafe22ab0a650996da2b3e5d94a12c3e16f3aa"},{"fixed":"52febaf1d311d6ede312b2ec7692a309714f9554"},{"fixed":"d5497644329d3a01e951aba76561bbd883ff6b0c"},{"fixed":"6a7d3b074cfbb64513f5f92d60ab1b216ae98076"},{"fixed":"b1881d362e1924b66f6016c3efd28807032b41bf"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90062.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"fixed":"5.10.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90062.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}