CVE-2026-72247
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conncount: fix zone comparison in tuple dedup
The "already exists" dedup logic in __nf_conncount_add() decides whether a connection has already been counted and can be skipped instead of incrementing the connlimit count. It compares the conntrack zone of a list entry with the zone of the connection being added using nf_ct_zone_id() and nf_ct_zone_equal(), passing conn->zone.dir or zone->dir as the direction argument.
Those helpers take enum ip_conntrack_dir values: IP_CT_DIR_ORIGINAL is 0 and IP_CT_DIR_REPLY is 1.
Leer descripción completaMostrar menos
However, zone->dir is a u8 bitmask: NF_CT_ZONE_DIR_ORIG is 1, NF_CT_ZONE_DIR_REPL is 2 and NF_CT_DEFAULT_ZONE_DIR is 3. Passing that bitmask as the enum direction shifts the meaning of every non-zero value. An ORIG-only zone passes 1 and is tested as REPLY, while REPL-only and default zones pass 2 or 3 and test bits beyond the valid direction range. In those cases nf_ct_zone_id() can fall back to NF_CT_DEFAULT_ZONE_ID instead of using the real zone id, so different zones can be treated as equal and dedup collapses to tuple equality alone.
nf_conncount stores and compares the original-direction tuple for a connection. If an skb already has an attached conntrack entry, get_ct_or_tuple_from_skb() explicitly copies ct->tuplehash[IP_CT_DIR_ORIGINAL].tuple, regardless of the packet's ctinfo. Therefore the zone comparison in the tuple dedup path must use IP_CT_DIR_ORIGINAL as well; the zone direction bitmask describes where a zone id applies, not which direction this conncount tuple represents.
Fix the two dedup comparisons by passing IP_CT_DIR_ORIGINAL directly. Do not special-case NF_CT_DEFAULT_ZONE_DIR and do not compare raw zone ids: using the existing helpers with IP_CT_DIR_ORIGINAL preserves the direction-aware NF_CT_DEFAULT_ZONE_ID fallback. A default bidirectional zone contains the ORIG bit, so it naturally returns the real zone id; reply-only zones continue to fall back for original-direction tuple comparisons.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.72%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access45 % - Impacto principal
T1499.004Application or System Exploitationimpact65 % - Impacto secundario
T1565.002Transmitted Data Manipulationimpact35 %
Vulnerabilidad remota de red (AV:N, PR:N, UI:N) en netfilter del kernel Linux. El defecto de comparación de zonas permite eludir limitadores de conexión (connlimit), causando negación de servicio por agotamiento de recursos o corrupción de conteos de conexión.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce
- https://git.kernel.org/stable/c/3cd9a5792cbea81139c24320986dd0db69e9b5d0
- https://git.kernel.org/stable/c/4f30a89c0ed2418719a1144881c2635b940b543d
- https://git.kernel.org/stable/c/6ff07ac5405bea4d4ead3559fc123f987576424a
- https://git.kernel.org/stable/c/78b5d6dbc860776161f9e9206b06ff8a01f531ab
- https://git.kernel.org/stable/c/7bdc3c0985ecf17b957811fedcc684acdf698acc
- https://git.kernel.org/stable/c/82fc35e0da9a91db9a034f8311f18f77a599ae3f
- https://git.kernel.org/stable/c/f62c41b4910e65da396ec9a8c40c1fe7fe82e449
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72247",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "21ba8847f857028dc83a0f341e16ecc616e34740",
"lessThan": "82fc35e0da9a91db9a034f8311f18f77a599ae3f",
"versionType": "git"
},
{
"status": "affected",
"version": "21ba8847f857028dc83a0f341e16ecc616e34740",
"lessThan": "78b5d6dbc860776161f9e9206b06ff8a01f531ab",
"versionType": "git"
},
{
"status": "affected",
"version": "21ba8847f857028dc83a0f341e16ecc616e34740",
"lessThan": "4f30a89c0ed2418719a1144881c2635b940b543d",
"versionType": "git"
},
{
"status": "affected",
"version": "21ba8847f857028dc83a0f341e16ecc616e34740",
"lessThan": "7bdc3c0985ecf17b957811fedcc684acdf698acc",
"versionType": "git"
},
{
"status": "affected",
"version": "21ba8847f857028dc83a0f341e16ecc616e34740",
"lessThan": "35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce",
"versionType": "git"
},
{
"status": "affected",
"version": "21ba8847f857028dc83a0f341e16ecc616e34740",
"lessThan": "3cd9a5792cbea81139c24320986dd0db69e9b5d0",
"versionType": "git"
},
{
"status": "affected",
"version": "21ba8847f857028dc83a0f341e16ecc616e34740",
"lessThan": "6ff07ac5405bea4d4ead3559fc123f987576424a",
"versionType": "git"
},
{
"status": "affected",
"version": "21ba8847f857028dc83a0f341e16ecc616e34740",
"lessThan": "f62c41b4910e65da396ec9a8c40c1fe7fe82e449",
"versionType": "git"
},
{
"status": "affected",
"version": "525e1dffed8711973f77412729621098a95238e5",
"versionType": "git"
},
{
"status": "affected",
"version": "75af3d78168e654a5cd8bbc4c774f97be836165f",
"versionType": "git"
},
{
"status": "affected",
"version": "4.14.92",
"lessThan": "4.15",
"versionType": "semver"
}
],
"programFiles": [
"net/netfilter/nf_conncount.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.18"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.18",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/netfilter/nf_conncount.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:51.887",
"references": [
{
"url": "https://git.kernel.org/stable/c/35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3cd9a5792cbea81139c24320986dd0db69e9b5d0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4f30a89c0ed2418719a1144881c2635b940b543d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6ff07ac5405bea4d4ead3559fc123f987576424a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/78b5d6dbc860776161f9e9206b06ff8a01f531ab",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7bdc3c0985ecf17b957811fedcc684acdf698acc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/82fc35e0da9a91db9a034f8311f18f77a599ae3f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f62c41b4910e65da396ec9a8c40c1fe7fe82e449",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conncount: fix zone comparison in tuple dedup\n\nThe \"already exists\" dedup logic in __nf_conncount_add() decides\nwhether a connection has already been counted and can be skipped instead\nof incrementing the connlimit count. It compares the conntrack zone of a\nlist entry with the zone of the connection being added using\nnf_ct_zone_id() and nf_ct_zone_equal(), passing conn->zone.dir or\nzone->dir as the direction argument.\n\nThose helpers take enum ip_conntrack_dir values: IP_CT_DIR_ORIGINAL is 0\nand IP_CT_DIR_REPLY is 1. However, zone->dir is a u8 bitmask:\nNF_CT_ZONE_DIR_ORIG is 1, NF_CT_ZONE_DIR_REPL is 2 and\nNF_CT_DEFAULT_ZONE_DIR is 3. Passing that bitmask as the enum direction\nshifts the meaning of every non-zero value. An ORIG-only zone passes 1\nand is tested as REPLY, while REPL-only and default zones pass 2 or 3 and\ntest bits beyond the valid direction range. In those cases\nnf_ct_zone_id() can fall back to NF_CT_DEFAULT_ZONE_ID instead of using\nthe real zone id, so different zones can be treated as equal and dedup\ncollapses to tuple equality alone.\n\nnf_conncount stores and compares the original-direction tuple for a\nconnection. If an skb already has an attached conntrack entry,\nget_ct_or_tuple_from_skb() explicitly copies\nct->tuplehash[IP_CT_DIR_ORIGINAL].tuple, regardless of the packet's\nctinfo. Therefore the zone comparison in the tuple dedup path must use\nIP_CT_DIR_ORIGINAL as well; the zone direction bitmask describes where a\nzone id applies, not which direction this conncount tuple represents.\n\nFix the two dedup comparisons by passing IP_CT_DIR_ORIGINAL directly.\nDo not special-case NF_CT_DEFAULT_ZONE_DIR and do not compare raw zone\nids: using the existing helpers with IP_CT_DIR_ORIGINAL preserves the\ndirection-aware NF_CT_DEFAULT_ZONE_ID fallback. A default bidirectional\nzone contains the ORIG bit, so it naturally returns the real zone id;\nreply-only zones continue to fall back for original-direction tuple\ncomparisons."
}
],
"lastModified": "2026-08-17T06:18:26.563",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}