SB20260816289 - Improper access control in Linux kernel netfilter
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-72247)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass connection counting limits.
The vulnerability exists due to improper access control in nf_conncount when processing connection tuples across conntrack zones. A remote attacker can send network traffic that creates connections with matching tuples in different zones to bypass connection counting limits.
The issue affects the tuple dedup logic in __nf_conncount_add(), where original-direction tuples are compared using an incorrect zone direction value.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce
- https://git.kernel.org/stable/c/3cd9a5792cbea81139c24320986dd0db69e9b5d0
- https://git.kernel.org/stable/c/4f30a89c0ed2418719a1144881c2635b940b543d
- https://git.kernel.org/stable/c/6ff07ac5405bea4d4ead3559fc123f987576424a
- https://git.kernel.org/stable/c/78b5d6dbc860776161f9e9206b06ff8a01f531ab
- https://git.kernel.org/stable/c/7bdc3c0985ecf17b957811fedcc684acdf698acc
- https://git.kernel.org/stable/c/82fc35e0da9a91db9a034f8311f18f77a599ae3f
- https://git.kernel.org/stable/c/f62c41b4910e65da396ec9a8c40c1fe7fe82e449