Resource exhaustion in Linux kernel - CVE-2026-45860
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in nf_conncount when tracking a high rate of new connections within the same jiffy. A remote attacker can send a large number of connection attempts to cause a denial of service.
The issue can be triggered in environments using nft_connlimit, xt_connlimit, or OVS limit configuration.
How to mitigate CVE-2026-45860
Sources
- https://git.kernel.org/stable/c/0792ad077d776c2dcf20f0484e2461ded1b77a24
- https://git.kernel.org/stable/c/0af0812baf2d363176c9b76fc07e33f13aede8db
- https://git.kernel.org/stable/c/13eede458fdf231f1bf96a398feea4ad1553f14c
- https://git.kernel.org/stable/c/21d033e472735ecec677f1ae46d6740b5e47a4f3
- https://git.kernel.org/stable/c/3d0994ed0aa1fc0a2c5e620b765e8defdd021bff
- https://git.kernel.org/stable/c/6e5fa7add3e76da068a478d905be64be8fa4e80a
- https://git.kernel.org/stable/c/a5c9e14e0e8923218ae881d5e78c990c07694966
- https://git.kernel.org/stable/c/fa85432d58c8e74b39333edbf8d28df2985dfc79