PT-2026-43726 · Linux+1 · Linux Kernel+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A regression in the netfilter nfnetlink queue component causes UDP packets to be dropped instead of queued. This occurs when an application has not set the
F GSO capability flag and a Generic Segmentation Offload (GSO) packet with an unconfirmed nf conn entry is received. The issue stems from the shared-unconfirmed check being performed after the skb gso segment() function, leading to an elevated use count due to skb clone and subsequent packet drops. This behavior is specific to UDP, as TCP SYN packets are not aggregated by Generic Receive Offload (GRO).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel