7.5
CVE-2026-72418
- EPSS 0.72%
- Veröffentlicht 15.08.2026 05:56:38
- Zuletzt bearbeitet 17.08.2026 06:19:08
- Erkennungen
netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
Commit 69894e5b4c5e ("netfilter: nft_connlimit: update the count if add
was skipped") introduced a regression where packets for valid
connections are dropped when using connlimit for soft-limiting
scenarios.
The issue occurs when a new connection reuses a socket currently in
the TIME_WAIT state. In this scenario, the connection tracking entry
is evaluated as already confirmed. Previously, __nf_conncount_add()
assumed that if a connection was confirmed and did not originate from
the loopback interface, it should skip the addition and return -EEXIST.
Skipping the addition triggers a garbage collection run that cleans up
the TIME_WAIT connection. Consequently, the active connection count
drops to 0, which xt_connlimit mishandles, leading to the false rejection
of the perfectly valid new connection.
Fix this by replacing the interface check with protocol-agnostic state
checks. We now skip the tree insertion and preserve the lockless garbage
collection optimization only if the connection is IPS_ASSURED. This
allows early-confirmed setup packets (such as reused TIME_WAIT sockets
or locally generated SYN-ACKs) to be properly evaluated and counted
without falsely dropping. The goto check_connections path is maintained
to ensure these setup packets are deduplicated correctly.
This has been tested with slowhttptest and HTTP server configured
locally to ensure we are not breaking soft-limiting scenarios for local
or external connections. In addition, it was tested with a OVS zone
limit too.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
460c112e1d887b58b06b56e8e0230058906ff2c3
Version <
000ac6830b56499d6b65fd91486ce6689eb02be4
Status
affected
Version
53bc0ac47f4f7621c991807bc90e01df49561ac8
Version <
cbe2d14a7c5b1fc71821fbfee5c4963917411e92
Status
affected
Version
ca8b4d1d6304a84ce2016fa2fe9a114b9607b839
Version <
3793d24de224943e0a6016bbeffb6f5c4cea2e3d
Status
affected
Version
8286c02fe9100330475331253fc590f047963f90
Version <
abef7f817217fcb62c11821d6b895063eadb2828
Status
affected
Version
b29ddccf36946a90323486221f39e9f88cc01b8e
Version <
ebfe8249ba79e4ff0f1e3aad8787b992ef27f026
Status
affected
Version
77ea3d8ac3d3d59b5ac9ad639e4ba107c0f2ff1e
Version <
329f2626ee5cb8fafdf6b58b624311529c57cb45
Status
affected
Version
69894e5b4c5e28cda5f32af33d4a92b7a4b93b0e
Version <
be52572c6d55f677ba76869d3c63805c0d4891a3
Status
affected
Version
69894e5b4c5e28cda5f32af33d4a92b7a4b93b0e
Version <
c8b6f36f766991e3ebebec6596daee4b04dcbc49
Status
affected
Version
f85623af16b83615e5f64a9b19ae1d584805cb07
Status
affected
Version
5.10.248
Version <
5.10.261
Status
affected
Version
5.15.198
Version <
5.15.212
Status
affected
Version
6.1.160
Version <
6.1.178
Status
affected
Version
6.6.120
Version <
6.6.145
Status
affected
Version
6.12.63
Version <
6.12.97
Status
affected
Version
6.18.2
Version <
6.18.40
Status
affected
Version
6.17.13
Version <
6.18
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.19
Status
affected
Version
0
Version <
6.19
Status
unaffected
Version <=
5.10.*
Version
5.10.261
Status
unaffected
Version <=
5.15.*
Version
5.15.212
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.72% | 0.507 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
https://git.kernel.org/stable/c/000ac6830b56499d6b65fd91486ce6689eb02be4
https://git.kernel.org/stable/c/cbe2d14a7c5b1fc71821fbfee5c4963917411e92
https://git.kernel.org/stable/c/3793d24de224943e0a6016bbeffb6f5c4cea2e3d
https://git.kernel.org/stable/c/abef7f817217fcb62c11821d6b895063eadb2828
https://git.kernel.org/stable/c/ebfe8249ba79e4ff0f1e3aad8787b992ef27f026
https://git.kernel.org/stable/c/329f2626ee5cb8fafdf6b58b624311529c57cb45
https://git.kernel.org/stable/c/be52572c6d55f677ba76869d3c63805c0d4891a3
https://git.kernel.org/stable/c/c8b6f36f766991e3ebebec6596daee4b04dcbc49