Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-45860— netfilter: nf_conncount: increase the connection clean up limit to 64

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于netfilter nf_conncount模块的连接清理限制过小,可能导致连接数错误达到上限。

CVSS 7.5 · High EPSS 0.68% · P49

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux f106694733c66a48740c25bc4e212e9b2ea364ce< a5c9e14e0e8923218ae881d5e78c990c07694966 affected
be69850b461e7b491d87a22e33ab76fdd04b725e< 13eede458fdf231f1bf96a398feea4ad1553f14c affected
d265929930e2ffafc744c0ae05fb70acd53be1ee< fa85432d58c8e74b39333edbf8d28df2985dfc79 affected
d265929930e2ffafc744c0ae05fb70acd53be1ee< 0792ad077d776c2dcf20f0484e2461ded1b77a24 affected
d265929930e2ffafc744c0ae05fb70acd53be1ee< 3d0994ed0aa1fc0a2c5e620b765e8defdd021bff affected
d265929930e2ffafc744c0ae05fb70acd53be1ee< 6e5fa7add3e76da068a478d905be64be8fa4e80a affected
d265929930e2ffafc744c0ae05fb70acd53be1ee< 0af0812baf2d363176c9b76fc07e33f13aede8db affected
d265929930e2ffafc744c0ae05fb70acd53be1ee< 21d033e472735ecec677f1ae46d6740b5e47a4f3 affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45860

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: nf_conncount: increase the connection clean up limit to 64
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection clean up limit to 64 After the optimization to only perform one GC per jiffy, a new problem was introduced. If more than 8 new connections are tracked per jiffy the list won't be cleaned up fast enough possibly reaching the limit wrongly. In order to prevent this issue, only skip the GC if it was already triggered during the same jiffy and the increment is lower than the clean up limit. In addition, increase the clean up limit to 64 connections to avoid triggering GC too often and do more effective GCs. This has been tested using a HTTP server and several performance tools while having nft_connlimit/xt_connlimit or OVS limit configured. Output of slowhttptest + OVS limit at 52000 connections: slow HTTP test status on 340th second: initializing: 0 pending: 432 connected: 51998 error: 0 closed: 0 service available: YES
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于netfilter nf_conncount模块的连接清理限制过小,可能导致连接数错误达到上限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux f106694733c66a48740c25bc4e212e9b2ea364ce ~ a5c9e14e0e8923218ae881d5e78c990c07694966 -
Linux Linux 5.19 -

II. Public POCs for CVE-2026-45860

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45860

登录查看更多情报信息。

Patches & Fixes for CVE-2026-45860 (8)

Same Patch Batch · Linux · 2026-05-27 · 275 CVEs total

CVE-2026-45898 9.8 CRITICAL RDMA/iwcm: Fix workqueue list corruption by removing work_list
CVE-2026-45988 9.8 CRITICAL rxrpc: Fix re-decryption of RESPONSE packets
CVE-2026-45972 9.8 CRITICAL smb: client: fix potential UAF and double free in smb2_open_file()
CVE-2026-46039 9.8 CRITICAL rxgk: Fix potential integer overflow in length check
CVE-2026-46043 9.1 CRITICAL RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
CVE-2026-45945 8.8 HIGH iommu/vt-d: Fix race condition during PASID entry replacement
CVE-2026-46056 8.8 HIGH Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
CVE-2026-46037 8.2 HIGH ipv4: icmp: validate reply type before using icmp_pointers
CVE-2025-71311 8.2 HIGH fs/ntfs3: Initialize new folios before use
CVE-2026-45843 8.2 HIGH slip: bound decode() reads against the compressed packet length
CVE-2026-46010 8.1 HIGH rxrpc: Fix error handling in rxgk_extract_token()
CVE-2026-46099 8.1 HIGH net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
CVE-2026-46076 7.9 HIGH KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-45935 7.8 HIGH fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot
CVE-2026-45909 7.8 HIGH clk: mediatek: Drop __initconst from gates
CVE-2026-45956 7.8 HIGH drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()
CVE-2026-45910 7.8 HIGH RDMA/rxe: Fix race condition in QP timer handlers
CVE-2026-45959 7.8 HIGH crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree
CVE-2026-45933 7.8 HIGH bpf: Preserve id of register in sync_linked_regs()
CVE-2026-45862 7.8 HIGH iommu/vt-d: Flush cache for PASID table before using it

Showing top 20 of 275 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-45860

No comments yet


Leave a comment