{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_log: unregister loggers before per-net teardown  nf_log_syslog and nfnetlink_log unregister their per-network namespace operations before unregistering their global logger backends. This leaves a window where a sysctl or netlink writer can rebind the still- registered logger after the per-net pre-exit callback cleared the old selection.  The race looks like this:    CPU 0                                 CPU 1   ----                                  ----   unregister_pernet_subsys()     nf_log_unset(net, logger)       net-\u003enf.nf_loggers[pf] = NULL                                          lock nf_log_mutex                                         find logger in loggers[][]                                         net-\u003enf.nf_loggers[pf] = logger                                         unlock nf_log_mutex    nf_log_unregister(logger)     lock nf_log_mutex     loggers[pf][type] = NULL     unlock nf_log_mutex     synchronize_rcu()   module exit returns   module core frees backend memory  Later, a sysctl read or packet logging operation can dereference the stale per-net logger pointer.  Fix this by unregistering the global logger backends before tearing down per-net state. Once the global registrations are gone, later writers can no longer rebind the logger. unregister_pernet_subsys() already waits for an RCU grace period after the pre-exit callback clears the per-net selection, while nf_log_unregister() continues to cover readers of the global logger table.  Apply this ordering fix to both nf_log backends that combine per-net teardown with global logger registration.",
  "id": "DEBIAN-CVE-2026-97608",
  "modified": "2026-09-26T04:47:28.885855471Z",
  "published": "2026-09-25T11:17:14.870Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97608"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-97608"
  ]
}