-

CVE-2026-72430

net/sched: act_ct: fix nf_connlabels leak on two error paths

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_ct: fix nf_connlabels leak on two error paths

tcf_ct_fill_params() calls nf_connlabels_get() (setting put_labels) when
TCA_CT_LABELS is present, but two later error sites use a bare return
instead of "goto err", skipping the err: nf_connlabels_put() cleanup.
They also precede the "p->put_labels = put_labels" assignment, so the
tcf_ct_params_free() fallback does not release the count either. Each
failed RTM_NEWACTION on these paths leaks one nf_connlabels reference:
net->ct.labels_used is incremented and never released. The action is
reachable with CAP_NET_ADMIN over the netns, i.e. from an unprivileged
user namespace on default-userns kernels.

Impact: an unprivileged user with CAP_NET_ADMIN over a network namespace
(e.g. via user namespaces) leaks one nf_connlabels reference per failed
RTM_NEWACTION on the two error paths; net->ct.labels_used is never
released.

The err: label is safe to reach from both sites: p->tmpl is still NULL
there (kzalloc'd, not yet assigned) and nf_ct_put(NULL) is a no-op, so
no inline release is needed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 70f06c115bcca26ceeebf938e48bc8143668e38b
Version < 13b561c893c741635adce3781490a7a1099106c8
Status affected
Version 70f06c115bcca26ceeebf938e48bc8143668e38b
Version < 1d51aff78f078af1a80e9496c2f4643f4c0ef0a0
Status affected
Version 70f06c115bcca26ceeebf938e48bc8143668e38b
Version < 0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4
Status affected
Version 70f06c115bcca26ceeebf938e48bc8143668e38b
Version < 16e088016f38cf728a0de709c3335cc5a3850476
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/13b561c893c741635adce3781490a7a1099106c8
https://git.kernel.org/stable/c/1d51aff78f078af1a80e9496c2f4643f4c0ef0a0
https://git.kernel.org/stable/c/0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4
https://git.kernel.org/stable/c/16e088016f38cf728a0de709c3335cc5a3850476