SB20260528212 - Resource exhaustion in Linux kernel netfilter
Published: May 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2026-45860)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in nf_conncount when tracking a high rate of new connections within the same jiffy. A remote attacker can send a large number of connection attempts to cause a denial of service.
The issue can be triggered in environments using nft_connlimit, xt_connlimit, or OVS limit configuration.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0792ad077d776c2dcf20f0484e2461ded1b77a24
- https://git.kernel.org/stable/c/0af0812baf2d363176c9b76fc07e33f13aede8db
- https://git.kernel.org/stable/c/13eede458fdf231f1bf96a398feea4ad1553f14c
- https://git.kernel.org/stable/c/21d033e472735ecec677f1ae46d6740b5e47a4f3
- https://git.kernel.org/stable/c/3d0994ed0aa1fc0a2c5e620b765e8defdd021bff
- https://git.kernel.org/stable/c/6e5fa7add3e76da068a478d905be64be8fa4e80a
- https://git.kernel.org/stable/c/a5c9e14e0e8923218ae881d5e78c990c07694966
- https://git.kernel.org/stable/c/fa85432d58c8e74b39333edbf8d28df2985dfc79