Kernel warning via expected ENOMEM rollback
Published Sep 3, 2026 · Updated Sep 3, 2026
Improper error handling in the Linux kernel allows attackers to trigger a warning during an nf_tables offload rollback. The nft_flow_rule_offload_abort function applies WARN_ON_ONCE to every rollback error, incorrectly treating an expected ENOMEM allocation failure as a kernel bug. Reachability requires an nf_tables transaction to enter the flow-offload rollback path while allocation fails; the documented consequence is a warning splat.
Summary
What happened
Improper error handling in the Linux kernel allows attackers to trigger a warning during an nf_tables offload rollback. The nft_flow_rule_offload_abort function applies WARN_ON_ONCE to every rollback error, incorrectly treating an expected ENOMEM allocation failure as a kernel bug. Reachability requires an nf_tables transaction to enter the flow-offload rollback path while allocation fails; the documented consequence is a warning splat.
The record
- CVE
- CVE-2026-80744
- Published
- Sep 3, 2026
- Updated
- Sep 3, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- Unavailable
- Attack vector
- local
- Privileges
- Unavailable
Timeline
How it unfolded
- Sep 3, 2026CVE publishedPublication date reported by the CVE source.
- Sep 3, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=5.5
- Affected versionversion=63b48c73ff567bbab1f940d6e8f3f48607077a13 <09bda4b6df222fd1819e8f188c3a6e90caf546d3
- Affected versionversion=63b48c73ff567bbab1f940d6e8f3f48607077a13 <17c132e18ca5d1641ddbaed8d0e6ecfd1d38fa0b
- Affected versionversion=63b48c73ff567bbab1f940d6e8f3f48607077a13 <2319033c4bf8bdb275a9e4e1f7af9bf8a457ad79
- Affected versionversion=63b48c73ff567bbab1f940d6e8f3f48607077a13 <4a923fe60939a194777bc605036ce2147ab00c9d
- Affected versionversion=63b48c73ff567bbab1f940d6e8f3f48607077a13 <6ee3803c22b72508c5baf1e5aecb21301b714be0
- Affected versionversion=63b48c73ff567bbab1f940d6e8f3f48607077a13 <7ce9851be6f2b019e96e105a9de99715aec6deb4
- Affected versionversion=63b48c73ff567bbab1f940d6e8f3f48607077a13 <c23620a0fa5b1d80399f894c41a9f78bc29d6235
- Affected versionversion=63b48c73ff567bbab1f940d6e8f3f48607077a13 <d02f592064347e0c1e0d84f24941ad338838cc48
What conditions does exploitation require?
What is affected?
Published CVSS scores
No CVSS assessment is available in this record.
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
No sourced classifications are available.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo