Description
In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_ct: preserve tc_skb_cb across defragmentation

tcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving
and restoring skb->cb. The defrag helper clears IPCB/IP6CB, which aliases
the tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through
act_ct therefore loses qdisc metadata such as pkt_segs and can trigger
WARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled.

Save and restore the full tc_skb_cb around nf_ct_handle_fragments(),
matching the pattern used by ovs_ct_handle_fragments().
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The kernel bug in the act_ct traffic control module causes the packet control buffer, tc_skb_cb, to be lost during defragmentation because nf_ct_handle_fragments() is called without saving and restoring skb->cb. This loss results in missing qdisc metadata such as packet segment counts. When the kernel is built with panic_on_warn enabled, the loss triggers WARN_ON_ONCE in the qdisc_pkt_segs() function, which can lead to a kernel panic. The weakness reflects improper handling of state across a defragmentation boundary, corresponding to CWE‑704 and CWE‑682.

Affected Systems

All Linux kernel installations that enable the act_ct qdisc module and process fragmented IP traffic. The correction is present in kernel patches referenced by the commit logs provided in the advisory; no specific version range is listed, so any kernel version following those commits is considered fixed.

Risk and Exploitability

The vulnerability is of high severity because it can cause a kernel crash, but its exploitation requires the attacker to craft fragmented IP packets that pass through the act_ct queue. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting that exploitation may be uncommon but the impact of a successful exploit would be complete denial of service. Official guidance indicates applying the kernel patch is the best mitigation. No exploit code is publicly disclosed, so the estimated likelihood of attack is low to moderate, yet the potential damage warrants immediate action.

Generated by OpenCVE AI on August 15, 2026 at 08:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the act_ct tc_skb_cb preservation patch referenced in the advisory commits.
  • Confirm that the act_ct or other traffic control modules are enabled in the kernel configuration and that the patch has been applied to those modules.
  • If a kernel update cannot be performed promptly, disable panic_on_warn in the kernel configuration to prevent kernel panic from the WARN_ON_ONCE messages generated by fragmented traffic.

Generated by OpenCVE AI on August 15, 2026 at 08:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-682
CWE-704

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: preserve tc_skb_cb across defragmentation tcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving and restoring skb->cb. The defrag helper clears IPCB/IP6CB, which aliases the tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through act_ct therefore loses qdisc metadata such as pkt_segs and can trigger WARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled. Save and restore the full tc_skb_cb around nf_ct_handle_fragments(), matching the pattern used by ovs_ct_handle_fragments().
Title net/sched: act_ct: preserve tc_skb_cb across defragmentation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:52:12.873Z

Reserved: 2026-08-09T03:40:39.903Z

Link: CVE-2026-72057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:15.153

Modified: 2026-08-15T06:21:15.153

Link: CVE-2026-72057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T08:45:05Z

Weaknesses
  • CWE-682

    Incorrect Calculation

  • CWE-704

    Incorrect Type Conversion or Cast