CVE-2026-64150: netfilter: nft_inner: release local_lock before re-enabling softirqs
Published Jul 19, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftinner: release locallock before re-enabling softirqs
Quoting sashiko: In the error path, localbhenable() is called before localunlocknestedbh().
Affected Software
7 affected components
Linux Linux kernel
Linux Linux kernel>=6.16<6.18.34
Linux Linux kernel>=6.19<7.0.11
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
Remediation
Event History
Jul 19, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverity
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-64150?
The severity of CVE-2026-64150 is critical with a CVSS score of 9.8.
2
What systems are affected by CVE-2026-64150?
CVE-2026-64150 affects versions of the Linux kernel that utilize the netfilter subsystem.
3
How do I fix CVE-2026-64150?
To fix CVE-2026-64150, update your Linux kernel to the latest version that addresses this vulnerability.
4
What are the potential impacts of CVE-2026-64150?
CVE-2026-64150 can lead to denial of service or system crashes due to improper handling of softirqs.
5
Is CVE-2026-64150 actively being exploited?
As of now, there are no confirmed reports of active exploitation for CVE-2026-64150.