Junglewise Threat Intelligence

CVE-2026-72418: Linux kernel netfilter nf_conncount denial of service

CVE-2026-72418 · Severity: high · CVSS 7.5 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's netfilter connection tracking subsystem has a flaw that causes valid network connections to be incorrectly rejected when reusing sockets in TIME_WAIT state. This impacts systems using connection limits for traffic shaping or load balancing, potentially causing legitimate client connections to fail and application availability to degrade.

Technical details

A regression in the netfilter nf_conncount module causes premature rejection of valid connections when a new connection reuses a socket in TIME_WAIT state. The vulnerable code incorrectly skips tree insertion for early-confirmed connections based on interface checks, triggering garbage collection that removes the TIME_WAIT entry and falsely reports zero active connections. An attacker or legitimate user can trigger this by establishing connections that reuse sockets, causing xt_connlimit to reject the valid new connection. The fix replaces interface checks with protocol-agnostic IPS_ASSURED state checks to properly track early-confirmed setup packets. Patches are available in the Linux kernel source.

Affected products

  • Linux Linux kernel versions with commit 69894e5b4c5e and later, prior to fix

Timeline

  • 2026-08-15: disclosed
  • patched: Fix available via Linux kernel patch

Related threats