« Volver al listado

CVE-2026-72430

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_ct: fix nf_connlabels leak on two error paths

tcf_ct_fill_params() calls nf_connlabels_get() (setting put_labels) when TCA_CT_LABELS is present, but two later error sites use a bare return instead of "goto err", skipping the err: nf_connlabels_put() cleanup. They also precede the "p->put_labels = put_labels" assignment, so the tcf_ct_params_free() fallback does not release the count either. Each failed RTM_NEWACTION on these paths leaks one nf_connlabels reference: net->ct.labels_used is incremented and never released. The action is reachable with CAP_NET_ADMIN over the netns, i.e. from an unprivileged user namespace on default-userns kernels.

Leer descripción completaMostrar menos

Impact: an unprivileged user with CAP_NET_ADMIN over a network namespace (e.g. via user namespaces) leaks one nf_connlabels reference per failed RTM_NEWACTION on the two error paths; net->ct.labels_used is never released.

The err: label is safe to reach from both sites: p->tmpl is still NULL there (kzalloc'd, not yet assigned) and nf_ct_put(NULL) is a no-op, so no inline release is needed.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72430",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "70f06c115bcca26ceeebf938e48bc8143668e38b",
              "lessThan": "13b561c893c741635adce3781490a7a1099106c8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "70f06c115bcca26ceeebf938e48bc8143668e38b",
              "lessThan": "1d51aff78f078af1a80e9496c2f4643f4c0ef0a0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "70f06c115bcca26ceeebf938e48bc8143668e38b",
              "lessThan": "0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "70f06c115bcca26ceeebf938e48bc8143668e38b",
              "lessThan": "16e088016f38cf728a0de709c3335cc5a3850476",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sched/act_ct.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sched/act_ct.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:16.863",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/13b561c893c741635adce3781490a7a1099106c8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/16e088016f38cf728a0de709c3335cc5a3850476",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1d51aff78f078af1a80e9496c2f4643f4c0ef0a0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix nf_connlabels leak on two error paths\n\ntcf_ct_fill_params() calls nf_connlabels_get() (setting put_labels) when\nTCA_CT_LABELS is present, but two later error sites use a bare return\ninstead of \"goto err\", skipping the err: nf_connlabels_put() cleanup.\nThey also precede the \"p->put_labels = put_labels\" assignment, so the\ntcf_ct_params_free() fallback does not release the count either. Each\nfailed RTM_NEWACTION on these paths leaks one nf_connlabels reference:\nnet->ct.labels_used is incremented and never released. The action is\nreachable with CAP_NET_ADMIN over the netns, i.e. from an unprivileged\nuser namespace on default-userns kernels.\n\nImpact: an unprivileged user with CAP_NET_ADMIN over a network namespace\n(e.g. via user namespaces) leaks one nf_connlabels reference per failed\nRTM_NEWACTION on the two error paths; net->ct.labels_used is never\nreleased.\n\nThe err: label is safe to reach from both sites: p->tmpl is still NULL\nthere (kzalloc'd, not yet assigned) and nf_ct_put(NULL) is a no-op, so\nno inline release is needed."
    }
  ],
  "lastModified": "2026-08-17T06:19:10.357",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}