netfilter: nf_tables: don't unregister hook when table is dormant
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't unregister hook when table is dormant When nf_tables_updchain encounters an error, hook registration needs to be rolled back. This should only be done if the hook has been registered, which won't happen when the table is flagged as dormant (inactive). Just move the assignment into the registration block.
02 / AFFECTED SOFTWARE
Affected packages
772 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't unregister hook when table is dormant When nf_tables_updchain encounters an error, hook registration needs to be rolled back. This should only be done if the hook has been registered, which won't happen when the table is flagged as dormant (inactive). Just move the assignment into the registration block.
05 / REFERENCES
Further evidence
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
- https://git.kernel.org/stable/c/03d1fb457b696c18fe15661440c4f052b2374e7e
- https://git.kernel.org/stable/c/6134d1ea1e1408e8e7c8c26545b3b301cbdf1eda
- https://git.kernel.org/stable/c/688c15017d5cd5aac882400782e7213d40dc3556
- https://git.kernel.org/stable/c/ce571eba07d54e3637bf334bc48376fbfa55defe
- https://git.kernel.org/stable/c/feb1fa2a03a27fec7001e93e4223be4120d1784b
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22064.json
- https://nvd.nist.gov/vuln/detail/CVE-2025-22064