Description: netfilter: nf_tables: fix use-after-free in nft_set_catchall_destroy() References: Notes: carnil> Introduced in aaa31047a6d2 ("netfilter: nftables: add catch-all set element carnil> support"). Vulnerable versions: 5.13-rc1. Bugs: upstream: released (5.16-rc7) [0f7d9b31ce7abdbb29bf018131ac920c9f698518] 6.7-upstream-stable: N/A "Fixed before branching point" 6.6-upstream-stable: N/A "Fixed before branching point" 6.1-upstream-stable: N/A "Fixed before branching point" 5.10-upstream-stable: N/A "Vulnerable code not present" 4.19-upstream-stable: N/A "Vulnerable code not present" sid: released (5.15.15-1) 6.1-bookworm-security: N/A "Fixed before branching point" 5.10-bullseye-security: N/A "Vulnerable code not present" 4.19-buster-security: N/A "Vulnerable code not present"