Impact
The vulnerability lies in the Linux kernel’s netfilter connection‑tracking (conntrack) subsystem. When a conntrack entry registers an expectation before the associated session is confirmed, the code places the expectation in a hash list that points to a memory region tied to the conntrack’s extension area. If that extension area is later reallocated, the pointer stored in the expectation’s .pprev field remains unchanged and points to the old hlist_head. When the kernel later dereferences this stale pointer during normal packet processing, it follows a corrupted list, which can lead to a kernel panic or other crash. The failure does not provide direct code execution or unauthorized access; the primary consequence is a denial of service through a host crash.
Affected Systems
All Linux kernel releases that have not incorporated commit 7c9664351980—which relocates the NAT hash list head to the main nf_conn structure—and the related helper release logic are affected. This includes many distribution kernels that still ship the older nft_ct module and its expectation handling code. Systems that run an unpatched kernel with the nf_ct module enabled, especially those using custom expectations or the nf_conntrack_helper subsystem, are at risk. Upstream patches that add the internal conntrack helper and the nf_conntrack_helper_release() routine address the issue.
Risk and Exploitability
The base CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score shows a very low exploitation probability (< 1%), and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely by sending specially crafted network traffic that causes an expectation to be added to an unconfirmed conntrack and then triggers extension reallocation. Local privilege escalation is not required. Given the remote trigger and the potentially catastrophic crash, patching should be prioritized even though the exploit chance is low.
OpenCVE Enrichment