Executive brief
The Linux kernel's netfilter connection tracking subsystem has a flaw that causes valid network connections to be incorrectly rejected when reusing sockets in TIME_WAIT state. This impacts systems using connection limits for traffic shaping or load balancing, potentially causing legitimate client connections to fail and application availability to degrade.
Technical details
A regression in the netfilter nf_conncount module causes premature rejection of valid connections when a new connection reuses a socket in TIME_WAIT state. The vulnerable code incorrectly skips tree insertion for early-confirmed connections based on interface checks, triggering garbage collection that removes the TIME_WAIT entry and falsely reports zero active connections. An attacker or legitimate user can trigger this by establishing connections that reuse sockets, causing xt_connlimit to reject the valid new connection. The fix replaces interface checks with protocol-agnostic IPS_ASSURED state checks to properly track early-confirmed setup packets. Patches are available in the Linux kernel source.
Affected products
- Linux Linux kernel versions with commit 69894e5b4c5e and later, prior to fix
Timeline
- 2026-08-15: disclosed
- patched: Fix available via Linux kernel patch