CVE-2026-45897

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_counter: serialize reset with spinlock Add a global static spinlock to serialize counter fetch+reset operations, preventing concurrent dump-and-reset from underrunning values. The lock is taken before fetching the total so that two parallel resets cannot both read the same counter values and then both subtract them. A global lock is used for simplicity since resets are infrequent. If this becomes a bottleneck, it can be replaced with a per-net lock later.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

03 Aug 2026, 10:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/48cf7918d10c66cb6b05226fa3fa5daf0c891089 -
  • () https://git.kernel.org/stable/c/cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1 -

25 Jun 2026, 21:09

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/0cdc6d5a26f2d1f7f15a43526841b679445c32e2 - () https://git.kernel.org/stable/c/0cdc6d5a26f2d1f7f15a43526841b679445c32e2 - Patch
References () https://git.kernel.org/stable/c/779c60a5190c42689534172f4b49e927c9959e4e - () https://git.kernel.org/stable/c/779c60a5190c42689534172f4b49e927c9959e4e - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

27 May 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 14:17

Updated : 2026-08-03 10:16


NVD link : CVE-2026-45897

Mitre link : CVE-2026-45897

CVE.ORG link : CVE-2026-45897


JSON object : View

Products Affected

linux

  • linux_kernel