CVE-2026-53269
netfilter: synproxy: add mutex to guard hook reference counting
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: add mutex to guard hook reference counting As the synproxy infrastructure register netfilter hooks on-demand when a user adds the first iptables target or nftables expression, if done concurrently they can race each other. Introduce a mutex to serialize the refcount control blocks access from both frontends. While a per namespace mutex might be more efficient, it is not needed for target/expression like SYNPROXY.
INFO
Published Date :
June 25, 2026, 9:16 a.m.
Last Modified :
July 8, 2026, 4:01 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Update the Linux kernel to the latest stable version.
- Ensure all system components are patched.
- Reboot the system after updates.
- Verify the kernel version.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-53269.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-53269 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-53269
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-53269 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-53269 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jul. 08, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Added CWE NVD-CWE-noinfo Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.176 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.143 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.210 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.36 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.94 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.13 *cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.3 up to (excluding) 5.10.259 Added Reference Type kernel.org: https://git.kernel.org/stable/c/0ec9ddc1bda261a2c57636c74c8b4e53000102c9 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/2fcba19caaeb2a33017459d3430f057967bb91b6 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/640441348258220e78daed40528b85b8afcedab6 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/aaf80701dc2f7a48fe543961e21f8ca3924d587c Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/debc57b83d5b323df74bf010c8d50fe26ad2ed6b Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/fbf0591275f50eae5733c3d7a8cd6c1e79933ffa Types: Patch -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 25, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ad49d86e07a497e834cb06f2b151dccd75f8e148', 'lessThan': '0ec9ddc1bda261a2c57636c74c8b4e53000102c9', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad49d86e07a497e834cb06f2b151dccd75f8e148', 'lessThan': '56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad49d86e07a497e834cb06f2b151dccd75f8e148', 'lessThan': 'debc57b83d5b323df74bf010c8d50fe26ad2ed6b', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad49d86e07a497e834cb06f2b151dccd75f8e148', 'lessThan': '0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad49d86e07a497e834cb06f2b151dccd75f8e148', 'lessThan': '640441348258220e78daed40528b85b8afcedab6', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad49d86e07a497e834cb06f2b151dccd75f8e148', 'lessThan': 'aaf80701dc2f7a48fe543961e21f8ca3924d587c', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad49d86e07a497e834cb06f2b151dccd75f8e148', 'lessThan': 'fbf0591275f50eae5733c3d7a8cd6c1e79933ffa', 'versionType': 'git'}, {'status': 'affected', 'version': 'ad49d86e07a497e834cb06f2b151dccd75f8e148', 'lessThan': '2fcba19caaeb2a33017459d3430f057967bb91b6', 'versionType': 'git'}], 'programFiles': ['net/netfilter/nf_synproxy_core.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.3'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.3', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.259', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.210', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.176', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.143', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.94', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.36', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.13', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/netfilter/nf_synproxy_core.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: add mutex to guard hook reference counting As the synproxy infrastructure register netfilter hooks on-demand when a user adds the first iptables target or nftables expression, if done concurrently they can race each other. Introduce a mutex to serialize the refcount control blocks access from both frontends. While a per namespace mutex might be more efficient, it is not needed for target/expression like SYNPROXY. Added Reference https://git.kernel.org/stable/c/0ec9ddc1bda261a2c57636c74c8b4e53000102c9 Added Reference https://git.kernel.org/stable/c/0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88 Added Reference https://git.kernel.org/stable/c/2fcba19caaeb2a33017459d3430f057967bb91b6 Added Reference https://git.kernel.org/stable/c/56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389 Added Reference https://git.kernel.org/stable/c/640441348258220e78daed40528b85b8afcedab6 Added Reference https://git.kernel.org/stable/c/aaf80701dc2f7a48fe543961e21f8ca3924d587c Added Reference https://git.kernel.org/stable/c/debc57b83d5b323df74bf010c8d50fe26ad2ed6b Added Reference https://git.kernel.org/stable/c/fbf0591275f50eae5733c3d7a8cd6c1e79933ffa