Impact
The bug causes ntckets rule handling to treat a template connection‑track entry as a genuine one, copying 16 bytes beyond a stack structure, which can corrupt kernel memory. An attacker could craft network traffic that is processed by the vulnerable nftables rule, potentially leading to arbitrary code execution or a kernel crash, thereby compromising the confidentiality, integrity, and availability of the host.
Affected Systems
All Linux kernels that include the nft_ct subsystem in nftables are affected, including recent 5.x and 6.x series. The vulnerability applies to the standard Linux:Linux product with nftables enabled, with no specific version exclusions noted.
Risk and Exploitability
not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. Nevertheless the nature of a kernel stack overflow places this issue at high severity; exploitation requires the ability to deliver crafted packets that trigger the overloaded rule, typically via the network. The risk to systems that run the old nftables configuration is significant, as exploitation could give an attacker kernel privileges.
OpenCVE Enrichment