CVE-2026-45859: Linux Kernel

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation Ulrich reports a regression with nfqueue: If an application did not set the 'F_GSO' capability flag and a gso packet with an unconfirmed nf_conn entry is received all packets are now dropped instead of queued, because the check happens after skb_gso_segment(). In that case, we did have exclusive ownership of the skb and its associated conntrack entry. The elevated use count is due to skb_clone happening via skb_gso_segment(). Move the check so that its peformed vs. the aggregated packet. Then, annotate the individual segments except the first one so we can do a 2nd check at reinject time. For the normal case, where userspace does in-order reinjects, this avoids packet drops: first reinjected segment continues traversal and confirms entry, remaining segments observe the confirmed entry. While at it, simplify nf_ct_drop_unconfirmed(): We only care about unconfirmed entries with a refcnt > 1, there is no need to special-case dying entries. This only happens with UDP. With TCP, the only unconfirmed packet will be the TCP SYN, those aren't aggregated by GRO. Next patch adds a udpgro test case to cover this scenario.

Affected products

  • Linux Linux Kernel: from 5.15.166, before 5.16 (fixed in 5.16); from 6.1.107, before 6.2 (fixed in 6.2); from 6.6.48, before 6.7 (fixed in 6.7); from 6.10.7, before 6.11 (fixed in 6.11); from 6.11.1, before 6.12.75 (fixed in 6.12.75); from 6.13, before 6.18.14 (fixed in 6.18.14); …

Published 2026-05-27. Last modified 2026-06-25.