PT-2026-43726 · Linux+1 · Linux Kernel+1

·

CVE-2026-45859

·

Published

2026-05-27

·

Updated

2026-07-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A regression in the netfilter nfnetlink queue component causes UDP packets to be dropped instead of queued. This occurs when an application has not set the F GSO capability flag and a Generic Segmentation Offload (GSO) packet with an unconfirmed nf conn entry is received. The issue stems from the shared-unconfirmed check being performed after the skb gso segment() function, leading to an elevated use count due to skb clone and subsequent packet drops. This behavior is specific to UDP, as TCP SYN packets are not aggregated by Generic Receive Offload (GRO).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-45859
OESA-2026-2869
OESA-2026-3157
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1

Affected Products

Linuxmint
Linux Kernel