Junglewise Threat Intelligence

CVE-2026-72057: Linux kernel act_ct tc_skb_cb metadata loss during defragmentation

CVE-2026-72057 · Severity: high · CVSS 8.2 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's traffic control (tc) packet scheduling module loses critical queueing metadata when processing fragmented network packets through connection tracking. This causes warnings and can trigger kernel panics on systems with panic-on-warn enabled, disrupting network services that rely on proper packet scheduling and quality-of-service handling.

Technical details

The vulnerability exists in net/sched/act_ct.c where tcf_ct_handle_fragments() calls nf_ct_handle_fragments() without preserving the tc_skb_cb control block. The defragmentation helper clears IPCB/IP6CB structures, which alias the tc_skb_cb/qdisc_skb_cb control buffer. This causes loss of qdisc metadata such as pkt_segs, triggering WARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled. The fix saves and restores the full tc_skb_cb structure around the defragmentation call, matching the pattern used by ovs_ct_handle_fragments(). The vulnerability affects fragmented traffic and is triggered by normal network operations without requiring special privileges or authentication.

Affected products

  • Linux Linux kernel Versions with net/sched act_ct subsystem (5.x and later); exact vulnerable range spans multiple kernel series

Timeline

  • 2026-08-15: disclosed: CVE-2026-72057 published
  • 2026-06-14: patched: Fix committed upstream (commit 9092e15defbe6c7bc241c306093ca9d358a578e7)

References

Related threats