CVE-2026-63913
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
20/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check<br />
<br />
An unintended behavior in the TCP conntrack state machine allows a<br />
connection to be forced into the CLOSE state using an RST packet with an<br />
invalid sequence number.<br />
<br />
Specifically, after a SYN packet is observed, an RST with an invalid SEQ<br />
can transition the conntrack entry to TCP_CONNTRACK_CLOSE, regardless of<br />
whether the RST corresponds to the expected reply direction. The relevant<br />
code path assumes the RST is a response to an outgoing SYN, but does not<br />
validate packet direction or ensure that a matching SYN was actually sent<br />
in the opposite direction.<br />
<br />
As a result, a crafted packet sequence consisting of a SYN followed by an<br />
invalid-sequence RST can prematurely terminate an active NAT entry. This<br />
makes connection teardown easier than intended.<br />
<br />
So, tighten the state transition logic to ensure that RST-triggered<br />
CLOSE transitions only occur when the RST is a valid response to a<br />
previously observed SYN in the correct direction.
Impacto
Puntuación base 3.x
8.20
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2006979a15af5404bf932a325357683c0bac1656
- https://git.kernel.org/stable/c/2bb6d82b586ea5a4cb73bbdd6b7432e96096bc77
- https://git.kernel.org/stable/c/6476c17d536dbd321c073242e762ddb2713a1238
- https://git.kernel.org/stable/c/b98ab51c45c5608a1c19ce7fd17a3032469bb83f
- https://git.kernel.org/stable/c/bed6e04be8e6b9133d8b16d5a42d0e0ce674fa9a
- https://git.kernel.org/stable/c/d67c6adee8d1b65330d0174c4c367faba14e80a8
- https://git.kernel.org/stable/c/f206def4e86d810f927ba1d8e322ea72b29bce58
- https://git.kernel.org/stable/c/f5547bebc416d56f56fb5b86dc20aabfa42165a0



