Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98251— openvswitch: avoid reallocating confirmed conntrack labels

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: openvswitch:避免对已确认的连接跟踪(conntrack)条目重新分配标签扩展 ovs_ct_get_conn_labels() 函数在 conntrack 条目尚无标签扩展时会添加该扩展。由于已确认状态的 conntrack 可以被无锁读取,此时添加扩展可能导致重新分配并释放扩展存储空间,而其他 CPU 正同时访问该扩展空间,从而引发竞争条件或数据不一致。 现仅对未确认状态的 conntrack 添加扩展。对于已确认状态但缺乏标签的 conntrack,其标签操

CVSS 7.8 · High EPSS 0.14% · P3

Possible ATT&CK Techniques 1 AI

T1564.001 · Hidden Files and Directories

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b< 4371d79ea74407fb992c985b1f94391e35bb8289 affected
c2ac667358708d7cce64c78f58af6adf4c1e848b< 7ff688aceada1160331a789385ea146f62fbddf7 affected
c2ac667358708d7cce64c78f58af6adf4c1e848b< 05eab8dced6bf4d3009a6eeee16ddac99047dc83 affected
c2ac667358708d7cce64c78f58af6adf4c1e848b< 579d87ec1e1e85729a6cb2c25961e58beb78640c affected
c2ac667358708d7cce64c78f58af6adf4c1e848b< 2e6dd889c325abf23821e1459c3ffef59b7f0009 affected
c2ac667358708d7cce64c78f58af6adf4c1e848b< d16f089bd700f45d720ce989d5495e1dc3be0cf8 affected
c2ac667358708d7cce64c78f58af6adf4c1e848b< 8c9fcc6c33950d3db551af664d1fd3d998bfee56 affected
c2ac667358708d7cce64c78f58af6adf4c1e848b< 3f118c8217c109fd13ca61caa301d72c483897ef affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98251

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
openvswitch: avoid reallocating confirmed conntrack labels
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: openvswitch: avoid reallocating confirmed conntrack labels ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry does not have one. Confirmed conntracks can be read locklessly, so adding an extension may reallocate and free the extension block while another CPU accesses it. Only add the extension for unconfirmed conntracks. A confirmed conntrack without labels now fails the caller's label operation instead of reallocating its extension storage.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux c2ac667358708d7cce64c78f58af6adf4c1e848b ~ 4371d79ea74407fb992c985b1f94391e35bb8289 -
Linux Linux 4.3 -

II. Public POCs for CVE-2026-98251

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98251

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98251 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98276 7.8 HIGH net: lock the socket in sock_gettstamp()
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98251

No comments yet


Leave a comment