Executive brief
The Linux kernel's netfilter connection tracking module can deadlock when processing invalid TCP or SCTP packets with certain logging configurations enabled. When a packet is flagged as invalid and logging is routed through netfilter's logging subsystem with conntrack export enabled, the logging code can re-enter and attempt to lock the same connection object that is already locked, causing the system to hang and potentially disrupting network connectivity.
Technical details
The vulnerability is a deadlock caused by recursive lock acquisition in the netfilter conntrack module. When TCP or SCTP conntrack handlers call nf_ct_l4proto_log_invalid() while holding ct->lock (the connection tracking lock), and logging is routed to nfnetlink_log with conntrack export enabled, the log handler can re-enter conntrack's netlink attribute dumping code (such as tcp_to_nlattr()), which attempts to acquire the same ct->lock again. The fix defers invalid packet logging until after the lock is released: the TCP/SCTP handlers now store minimal logging context while holding ct->lock, then emit the actual log message after calling spin_unlock_bh(&ct->lock). A lockdep assertion was added to catch future violations outside these two protocols.
Affected products
- Linux Linux kernel Affected versions across stable series from 2.6.11 through 7.2
Timeline
- 2026-08-22: disclosed: Published to NVD
- 2026-08-01: patched: Patch committed upstream by Zihan Xi
- 2026-08-10: patched: Patch merged into Pablo Neira Ayuso's netfilter tree
- 2026-08-19: patched: Patch released in stable kernels by Greg Kroah-Hartman