Junglewise Threat Intelligence

CVE-2026-63913: Linux Kernel Netfilter connection termination via invalid TCP RST

CVE-2026-63913 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow an attacker to prematurely terminate active network connections. By sending specially crafted network packets, an attacker can trick the system into closing connection entries in the firewall's state table. This can lead to service disruptions and the unexpected termination of legitimate network traffic.

Technical details

A flaw exists in the TCP conntrack state machine within the Linux kernel's Netfilter subsystem. Specifically, the logic in nf_conntrack_proto_tcp.c fails to validate the packet direction when processing an RST packet with an invalid sequence number after a SYN packet is observed. This allows an RST packet to transition a connection entry to TCP_CONNTRACK_CLOSE even if it does not correspond to the expected reply direction. An attacker can exploit this by sending a SYN followed by a crafted RST to prematurely terminate NAT entries or firewall states. The issue has been resolved by tightening the state transition logic to ensure RST-triggered CLOSE transitions only occur for valid responses in the correct direction.

Affected products

  • Linux Linux Kernel 9fb9cbb1082d to 2006979a15af5404bf932a325357683c0bac1656

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References

Related threats