PT-2026-37426 · Linux · Linux Kernel

Published

2026-05-06

·

Updated

2026-05-08

·

CVE-2026-43116

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw in the netfilter ctnetlink component allows for unsafe access to the master conntrack object. Holding a reference to the expectation is insufficient because the master conntrack object can be removed, rendering exp->master invalid. This occurs during the delete expectation command, the get expectation command, and during the delivery of the IPEXP NEW event, where the master conntrack event cache is accessed via exp->master.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2026-43116

Affected Products

Linux Kernel