SB2026032555 - Resource exhaustion in Linux kernel netfilter



SB2026032555 - Resource exhaustion in Linux kernel netfilter

Published: March 25, 2026

Security Bulletin ID SB2026032555
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource exhaustion (CVE-ID: CVE-2026-23391)

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in the netfilter xt_CT module when handling packet queueing. A local user can trigger the queuing of packets that reference templates, which, upon removal of the template, are not properly flushed, leading to resource exhaustion and system instability.

Templates such as connection tracking helpers or timeout policies may be removed during module unloading or via nfnetlink_cttimeout, leaving packets enqueued without valid references.


Remediation

Install update from vendor's website.