Linux Kernel Netfilter CTNetlink Master Connection Tracking Access Vulnerability

Vulnerability

A vulnerability in the Linux kernel's netfilter component can lead to improper handling of connection tracking expectations. The issue arises because holding a reference to an expectation is not enough; the master connection tracking object can be deleted, rendering the reference invalid. This vulnerability affects the Linux kernel stable tree.

Impact

This vulnerability could lead to use-after-free conditions, where a reference to a deleted object is still being used, potentially causing memory corruption or other unintended behavior.

Remediation

Users can apply the patch available in the Linux kernel stable tree to address this vulnerability.

Added: May 6, 2026, 10:30 AM
Updated: May 6, 2026, 10:30 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
3.0
remediation
7.7
relevance
7.6
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.