CVE-2026-43060 PUBLISHED

netfilter: nft_ct: drop pending enqueued packets on removal

Assigner: Linux
Reserved: 01.05.2026 Published: 05.05.2026 Updated: 05.05.2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_ct: drop pending enqueued packets on removal

Packets sitting in nfqueue might hold a reference to:

  • templates that specify the conntrack zone, because a percpu area is used and module removal is possible.
  • conntrack timeout policies and helper, where object removal leave a stale reference.

Since these objects can just go away, drop enqueued packets to avoid stale reference to them.

If there is a need for finer grain removal, this logic can be revisited to make selective packet drop upon dependencies.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 7e0b2b57f01d183e1c84114f1f2287737358d748 to 8a64e76933672b08bd85b63086f33432070fd729 (excl.)
  • affected from 7e0b2b57f01d183e1c84114f1f2287737358d748 to 3da0b946835f33bf36b459ead764c61a761e689b (excl.)
  • affected from 7e0b2b57f01d183e1c84114f1f2287737358d748 to ab50302190b303f847c4eba0e31a01a56dec596e (excl.)
  • affected from 7e0b2b57f01d183e1c84114f1f2287737358d748 to e68a8db3a0546482b34e9ca5ca886bcf73eb37bb (excl.)
  • affected from 7e0b2b57f01d183e1c84114f1f2287737358d748 to 6802ff8beceb9c4254318e81c1395720438f2cc2 (excl.)
  • affected from 7e0b2b57f01d183e1c84114f1f2287737358d748 to f29a055e4f593e577805b41228b142b58f48df1b (excl.)
  • affected from 7e0b2b57f01d183e1c84114f1f2287737358d748 to 77da55dee67720e2b8d2db49a53334e6c017ee7b (excl.)
  • affected from 7e0b2b57f01d183e1c84114f1f2287737358d748 to 36eae0956f659e48d5366d9b083d9417f3263ddc (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.19 is affected
  • unaffected from 0 to 4.19 (excl.)
  • unaffected from 5.10.253 to 5.10.* (incl.)
  • unaffected from 5.15.203 to 5.15.* (incl.)
  • unaffected from 6.1.167 to 6.1.* (incl.)
  • unaffected from 6.6.130 to 6.6.* (incl.)
  • unaffected from 6.12.78 to 6.12.* (incl.)
  • unaffected from 6.18.20 to 6.18.* (incl.)
  • unaffected from 6.19.10 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References