Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63913

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
20/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check<br /> <br /> An unintended behavior in the TCP conntrack state machine allows a<br /> connection to be forced into the CLOSE state using an RST packet with an<br /> invalid sequence number.<br /> <br /> Specifically, after a SYN packet is observed, an RST with an invalid SEQ<br /> can transition the conntrack entry to TCP_CONNTRACK_CLOSE, regardless of<br /> whether the RST corresponds to the expected reply direction. The relevant<br /> code path assumes the RST is a response to an outgoing SYN, but does not<br /> validate packet direction or ensure that a matching SYN was actually sent<br /> in the opposite direction.<br /> <br /> As a result, a crafted packet sequence consisting of a SYN followed by an<br /> invalid-sequence RST can prematurely terminate an active NAT entry. This<br /> makes connection teardown easier than intended.<br /> <br /> So, tighten the state transition logic to ensure that RST-triggered<br /> CLOSE transitions only occur when the RST is a valid response to a<br /> previously observed SYN in the correct direction.