Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_ct: move custom expectation support to helper

Originally, the ct expectation support called nf_ct_helper_ext_add() for
confirmed conntracks, which is invalid, triggering a splat. This was
fixed by commit 1710eb913bdc ("netfilter: nft_ct: skip expectations for
confirmed conntrack") which restricted it to unconfirmed conntracks.

However, early insertion of expectations into the expectations list when
the conntrack is unconfirmed leads to stale entries pointing to the
wrong hlist_head through .pprev due to ct extension reallocation.

Commit 7c9664351980 ("netfilter: move nat hlist_head to nf_conn") moved
the nat hlist_head to nf_conn for this reason:

1. ...
2. When reallocation of extension area occurs we need to fixup the
bysource hash head via hlist_replace_rcu.

I'd rather not increase the size of the struct nf_conn for this feature
has very limited scope: only one expectation can be created at a time
given expect_clash() will make nf_ct_expect_related() reports EBUSY.
For this reason, relax nf_ct_expect_related() not to drop packets in
case expectation creation fails, therefore, expectation creation becomes
best effort.

To address this issue, add an internal ct helper and attach it to the
conntrack entry to streamline the custom ct expectation support with
existing ct helpers.

Expose a new nf_conntrack_helper_release() function to release the
internal helper that is allocated and attached to the conntrack entry to
create the custom expectations. The nft_ct module removal always waits
for rcu grace period, then the NULL helper callback is observed after
this.

This patch also restricts the creation of expectations to different
helpers other than this custom helper that is created for this type of
expectations.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash
Action: Patch Immediately
AI Analysis

Impact

The vulnerability lies in the Linux kernel’s netfilter connection‑tracking (conntrack) subsystem. When a conntrack entry registers an expectation before the associated session is confirmed, the code places the expectation in a hash list that points to a memory region tied to the conntrack’s extension area. If that extension area is later reallocated, the pointer stored in the expectation’s .pprev field remains unchanged and points to the old hlist_head. When the kernel later dereferences this stale pointer during normal packet processing, it follows a corrupted list, which can lead to a kernel panic or other crash. The failure does not provide direct code execution or unauthorized access; the primary consequence is a denial of service through a host crash.

Affected Systems

All Linux kernel releases that have not incorporated commit 7c9664351980—which relocates the NAT hash list head to the main nf_conn structure—and the related helper release logic are affected. This includes many distribution kernels that still ship the older nft_ct module and its expectation handling code. Systems that run an unpatched kernel with the nf_ct module enabled, especially those using custom expectations or the nf_conntrack_helper subsystem, are at risk. Upstream patches that add the internal conntrack helper and the nf_conntrack_helper_release() routine address the issue.

Risk and Exploitability

The base CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score shows a very low exploitation probability (< 1%), and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely by sending specially crafted network traffic that causes an expectation to be added to an unconfirmed conntrack and then triggers extension reallocation. Local privilege escalation is not required. Given the remote trigger and the potentially catastrophic crash, patching should be prioritized even though the exploit chance is low.

Generated by OpenCVE AI on September 20, 2026 at 04:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes commit 7c9664351980 and the helper release function, or apply the upstream patch directly if upgrading is not immediately possible.
  • If an upgrade cannot be performed right away, disable the vulnerable code path by setting the sysctl net.netfilter.nf_conntrack_expect_max=0 or unloading the nf_ct module to prevent expectation creation.
  • For environments that do not require conntrack expectations, blacklist or permanently disable the nf_ct module with modprobe blacklist or a similar mechanism to eliminate the crash vector.

Generated by OpenCVE AI on September 20, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-665

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-665

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: move custom expectation support to helper Originally, the ct expectation support called nf_ct_helper_ext_add() for confirmed conntracks, which is invalid, triggering a splat. This was fixed by commit 1710eb913bdc ("netfilter: nft_ct: skip expectations for confirmed conntrack") which restricted it to unconfirmed conntracks. However, early insertion of expectations into the expectations list when the conntrack is unconfirmed leads to stale entries pointing to the wrong hlist_head through .pprev due to ct extension reallocation. Commit 7c9664351980 ("netfilter: move nat hlist_head to nf_conn") moved the nat hlist_head to nf_conn for this reason: 1. ... 2. When reallocation of extension area occurs we need to fixup the bysource hash head via hlist_replace_rcu. I'd rather not increase the size of the struct nf_conn for this feature has very limited scope: only one expectation can be created at a time given expect_clash() will make nf_ct_expect_related() reports EBUSY. For this reason, relax nf_ct_expect_related() not to drop packets in case expectation creation fails, therefore, expectation creation becomes best effort. To address this issue, add an internal ct helper and attach it to the conntrack entry to streamline the custom ct expectation support with existing ct helpers. Expose a new nf_conntrack_helper_release() function to release the internal helper that is allocated and attached to the conntrack entry to create the custom expectations. The nft_ct module removal always waits for rcu grace period, then the NULL helper callback is observed after this. This patch also restricts the creation of expectations to different helpers other than this custom helper that is created for this type of expectations.
Title netfilter: nft_ct: move custom expectation support to helper
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:03.145Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90237

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:19.640

Modified: 2026-09-18T18:17:50.027

Link: CVE-2026-90237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses