CVE-2026-31414
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
13/04/2026
Última modificación:
13/04/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: nf_conntrack_expect: use expect->helper<br />
<br />
Use expect->helper in ctnetlink and /proc to dump the helper name.<br />
Using nfct_help() without holding a reference to the master conntrack<br />
is unsafe.<br />
<br />
Use exp->master->helper in ctnetlink path if userspace does not provide<br />
an explicit helper when creating an expectation to retain the existing<br />
behaviour. The ctnetlink expectation path holds the reference on the<br />
master conntrack and nf_conntrack_expect lock and the nfnetlink glue<br />
path refers to the master ct that is attached to the skb.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/3dfd3f7712b5a800f2ba632179e9b738076a51f0
- https://git.kernel.org/stable/c/4bd1b3d839172724b33d8d02c5a4ff6a1c775417
- https://git.kernel.org/stable/c/847cb7fe26c5ce5dce0d1a41fac1ea488b7f1781
- https://git.kernel.org/stable/c/b53294bff19e56ada2f230ceb8b1ffde61cc3817
- https://git.kernel.org/stable/c/e7ccaa0a62a8ff2be5d521299ce79390c318d306
- https://git.kernel.org/stable/c/f01794106042ee27e54af6fdf5b319a2fe3df94d



