CVE-2026-72418: Linux

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: prevent connlimit drops for early confirmed ct Commit 69894e5b4c5e ("netfilter: nft_connlimit: update the count if add was skipped") introduced a regression where packets for valid connections are dropped when using connlimit for soft-limiting scenarios. The issue occurs when a new connection reuses a socket currently in the TIME_WAIT state. In this scenario, the connection tracking entry is evaluated as already confirmed. Previously, __nf_conncount_add() assumed that if a connection was confirmed and did not originate from the loopback interface, it should skip the addition and return -EEXIST. Skipping the addition triggers a garbage collection run that cleans up the TIME_WAIT connection. Consequently, the active connection count drops to 0, which xt_connlimit mishandles, leading to the false rejection of the perfectly valid new connection. Fix this by replacing the interface check with protocol-agnostic state checks. We now skip the tree insertion and preserve the lockless garbage collection optimization only if the connection is IPS_ASSURED. This allows early-confirmed setup packets (such as reused TIME_WAIT sockets or locally generated SYN-ACKs) to be properly evaluated and counted without falsely dropping. The goto check_connections path is maintained to ensure these setup packets are deduplicated correctly. This has been tested with slowhttptest and HTTP server configured locally to ensure we are not breaking soft-limiting scenarios for local or external connections. In addition, it was tested with a OVS zone limit too.

Affected products

  • Linux Linux: from 5.10.248, before 5.10.261 (fixed in 5.10.261); from 5.15.198, before 5.15.212 (fixed in 5.15.212); from 6.1.160, before 6.1.178 (fixed in 6.1.178); from 6.6.120, before 6.6.145 (fixed in 6.6.145); from 6.12.63, before 6.12.97 (fixed in 6.12.97); from 6.18.2, before 6.18.40 (fixed in 6.18.40); …

Published 2026-08-15. Last modified 2026-08-17.