CVE-2026-74625
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: bridge: release template ct on non-IP path<br />
<br />
A bridge nftables ct zone set rule can attach a conntrack template to<br />
an skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6<br />
EtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with<br />
IP_CT_UNTRACKED without releasing the existing template reference.<br />
<br />
That makes the per-cpu template, and any temporary templates allocated<br />
for concurrent use, unreachable and leaks memory until the host runs out<br />
of slab.<br />
<br />
Reset the skb conntrack state before marking the frame untracked so the<br />
existing template reference is dropped on the non-IP path.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd
- https://git.kernel.org/stable/c/6ea88401e10e04e0b3bb7a7adea54932fb60b93b
- https://git.kernel.org/stable/c/7cff440d702616022769f2643168d7f9820547a0
- https://git.kernel.org/stable/c/bd7b16494dacf87e9336a1dcfdada83b9e40edd6
- https://git.kernel.org/stable/c/c58d34fe8b7e47bb0b350a7625023b1261342be5
- https://git.kernel.org/stable/c/d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f
- https://git.kernel.org/stable/c/daa6e070f8e1e7a4dddec8b64ca37663f8cda917
- https://git.kernel.org/stable/c/fc90df37540627d092af770215fb4b7befe9409b


