Junglewise Threat Intelligence

CVE-2026-45860: Linux kernel netfilter resource exhaustion in nf_conncount

CVE-2026-45860 · Severity: info · CVSS 5.3 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a remote attacker to cause a denial-of-service condition. The issue affects the netfilter component, which is responsible for managing network traffic and firewall rules. Under specific high-traffic conditions, the system may fail to properly clean up old connection records, leading to resource exhaustion and the inability to accept new legitimate connections.

Technical details

A vulnerability in the nf_conncount garbage collection (GC) logic in the Linux kernel was identified where an optimization to limit GC to once per jiffy caused issues under high load. If more than 8 new connections are tracked per jiffy, the connection list is not cleaned up fast enough, causing the system to incorrectly reach connection limits. This is a resource management issue where stale entries are not evicted promptly. The fix involves increasing the cleanup limit to 64 connections and adjusting the GC trigger logic to ensure effective cleanup when connection increments exceed the threshold within the same jiffy. This affects systems using nft_connlimit, xt_connlimit, or Open vSwitch (OVS) connection limits.

Affected products

  • Linux Linux kernel All versions prior to the fix in 2026-03-04

Timeline

  • 2025-12-17: other: Patch authored
  • 2026-03-04: patched: Patch committed to stable tree
  • 2026-05-27: advisory: CVE published

References

Related threats