HIGHCVE-2026-43060Published Modified CNA Linux
CVE-2026-43060: netfilter: nft_ct: drop pending enqueued packets on removal
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: drop pending enqueued packets on removal Packets sitting in nfqueue might hold a reference to: - templates that specify the conntrack zone, because a percpu area is used and module removal is possible. - conntrack timeout policies and helper, where object removal leave a stale reference. Since these objects can just go away, drop enqueued packets to avoid stale reference to them. If there is a need for finer grain removal, this logic can be revisited to make selective packet drop upon dependencies.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
036eae0956f659e48d5366d9b083d9417f3263ddc3da0b946835f33bf36b459ead764c61a761e689b5.10.2535.15.2036.1.1676.6.1306.12.786.18.206.19.106802ff8beceb9c4254318e81c1395720438f2cc27.077da55dee67720e2b8d2db49a53334e6c017ee7b8a64e76933672b08bd85b63086f33432070fd729ab50302190b303f847c4eba0e31a01a56dec596ee68a8db3a0546482b34e9ca5ca886bcf73eb37bbf29a055e4f593e577805b41228b142b58f48df1b
Affected packages
- Linux / Linux< 8a64e76933672b08bd85b63086f33432070fd729 (from 7e0b2b57f01d183e1c84114f1f2287737358d748) · < 3da0b946835f33bf36b459ead764c61a761e689b (from 7e0b2b57f01d183e1c84114f1f2287737358d748) · < ab50302190b303f847c4eba0e31a01a56dec596e (from 7e0b2b57f01d183e1c84114f1f2287737358d748) · < e68a8db3a0546482b34e9ca5ca886bcf73eb37bb (from 7e0b2b57f01d183e1c84114f1f2287737358d748) · < 6802ff8beceb9c4254318e81c1395720438f2cc2 (from 7e0b2b57f01d183e1c84114f1f2287737358d748) · < f29a055e4f593e577805b41228b142b58f48df1b (from 7e0b2b57f01d183e1c84114f1f2287737358d748)
- Linux / Linux4.19Fixed in 0, 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H