Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72418— netfilter: nf_conncount: prevent connlimit drops for early confirmed ct

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于在connlimit软限制场景中,当新连接重用TIME_WAIT状态socket时连接计数处理不当,可能导致有效的网络连接被错误丢弃。

CVSS 7.5 · High EPSS 0.71% · P51

Possible ATT&CK Techniques 1 AI

T1498.002 · Reflection Amplification

Affected Version Matrix 26

VendorProduct Version RangeStatus
Linux Linux 460c112e1d887b58b06b56e8e0230058906ff2c3< 000ac6830b56499d6b65fd91486ce6689eb02be4 affected
53bc0ac47f4f7621c991807bc90e01df49561ac8< cbe2d14a7c5b1fc71821fbfee5c4963917411e92 affected
ca8b4d1d6304a84ce2016fa2fe9a114b9607b839< 3793d24de224943e0a6016bbeffb6f5c4cea2e3d affected
8286c02fe9100330475331253fc590f047963f90< abef7f817217fcb62c11821d6b895063eadb2828 affected
b29ddccf36946a90323486221f39e9f88cc01b8e< ebfe8249ba79e4ff0f1e3aad8787b992ef27f026 affected
77ea3d8ac3d3d59b5ac9ad639e4ba107c0f2ff1e< 329f2626ee5cb8fafdf6b58b624311529c57cb45 affected
69894e5b4c5e28cda5f32af33d4a92b7a4b93b0e< be52572c6d55f677ba76869d3c63805c0d4891a3 affected
69894e5b4c5e28cda5f32af33d4a92b7a4b93b0e< c8b6f36f766991e3ebebec6596daee4b04dcbc49 affected
… +18 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72418

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: prevent connlimit drops for early confirmed ct Commit 69894e5b4c5e ("netfilter: nft_connlimit: update the count if add was skipped") introduced a regression where packets for valid connections are dropped when using connlimit for soft-limiting scenarios. The issue occurs when a new connection reuses a socket currently in the TIME_WAIT state. In this scenario, the connection tracking entry is evaluated as already confirmed. Previously, __nf_conncount_add() assumed that if a connection was confirmed and did not originate from the loopback interface, it should skip the addition and return -EEXIST. Skipping the addition triggers a garbage collection run that cleans up the TIME_WAIT connection. Consequently, the active connection count drops to 0, which xt_connlimit mishandles, leading to the false rejection of the perfectly valid new connection. Fix this by replacing the interface check with protocol-agnostic state checks. We now skip the tree insertion and preserve the lockless garbage collection optimization only if the connection is IPS_ASSURED. This allows early-confirmed setup packets (such as reused TIME_WAIT sockets or locally generated SYN-ACKs) to be properly evaluated and counted without falsely dropping. The goto check_connections path is maintained to ensure these setup packets are deduplicated correctly. This has been tested with slowhttptest and HTTP server configured locally to ensure we are not breaking soft-limiting scenarios for local or external connections. In addition, it was tested with a OVS zone limit too.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于在connlimit软限制场景中,当新连接重用TIME_WAIT状态socket时连接计数处理不当,可能导致有效的网络连接被错误丢弃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 460c112e1d887b58b06b56e8e0230058906ff2c3 ~ 000ac6830b56499d6b65fd91486ce6689eb02be4 -
Linux Linux 6.19 -

II. Public POCs for CVE-2026-72418

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72418

登录查看更多情报信息。

Patches & Fixes for CVE-2026-72418 (7)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-72069 9.8 CRITICAL locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
CVE-2026-72234 9.8 CRITICAL batman-adv: access unicast_ttvn skb->data only after skb realloc
CVE-2026-72339 9.8 CRITICAL qede: fix off-by-one in BD ring consumption on build_skb failure
CVE-2026-74255 9.8 CRITICAL tipc: fix UAF in tipc_l2_send_msg()
CVE-2026-72064 9.8 CRITICAL net: mana: Sync page pool RX frags for CPU
CVE-2026-72065 9.8 CRITICAL net: mana: Validate the packet length reported by the NIC
CVE-2026-72217 9.8 CRITICAL SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
CVE-2026-74473 9.8 CRITICAL vxlan: use pskb_network_may_pull() in route_shortcircuit()
CVE-2026-72323 9.8 CRITICAL ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
CVE-2026-74376 9.8 CRITICAL md/raid10: reset read_slot when reusing r10bio for discard
CVE-2026-72463 9.8 CRITICAL xfrm: Fix dev use-after-free in xfrm async resumption
CVE-2026-74495 9.8 CRITICAL igbvf: Fix leak in TX DMA error cleanup

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72418

No comments yet


Leave a comment