Improper access control in Linux kernel - CVE-2026-72247
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass connection counting limits.
The vulnerability exists due to improper access control in nf_conncount when processing connection tuples across conntrack zones. A remote attacker can send network traffic that creates connections with matching tuples in different zones to bypass connection counting limits.
The issue affects the tuple dedup logic in __nf_conncount_add(), where original-direction tuples are compared using an incorrect zone direction value.
Affected software
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-extra-modules
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
How to mitigate CVE-2026-72247
kernel - update to 6.6.0-145.3.31.162
bpftool - update to 6.6.0-145.3.31.162
bpftool-debuginfo - update to 6.6.0-145.3.31.162
kernel-debuginfo - update to 6.6.0-145.3.31.162
kernel-debugsource - update to 6.6.0-145.3.31.162
kernel-devel - update to 6.6.0-145.3.31.162
kernel-extra-modules - update to 6.6.0-145.3.31.162
kernel-headers - update to 6.6.0-145.3.31.162
kernel-source - update to 6.6.0-145.3.31.162
kernel-tools - update to 6.6.0-145.3.31.162
kernel-tools-debuginfo - update to 6.6.0-145.3.31.162
kernel-tools-devel - update to 6.6.0-145.3.31.162
perf - update to 6.6.0-145.3.31.162
perf-debuginfo - update to 6.6.0-145.3.31.162
python3-perf - update to 6.6.0-145.3.31.162
python3-perf-debuginfo - update to 6.6.0-145.3.31.162
External References
- https://git.kernel.org/stable/c/35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce
- https://git.kernel.org/stable/c/3cd9a5792cbea81139c24320986dd0db69e9b5d0
- https://git.kernel.org/stable/c/4f30a89c0ed2418719a1144881c2635b940b543d
- https://git.kernel.org/stable/c/6ff07ac5405bea4d4ead3559fc123f987576424a
- https://git.kernel.org/stable/c/78b5d6dbc860776161f9e9206b06ff8a01f531ab
- https://git.kernel.org/stable/c/7bdc3c0985ecf17b957811fedcc684acdf698acc
- https://git.kernel.org/stable/c/82fc35e0da9a91db9a034f8311f18f77a599ae3f
- https://git.kernel.org/stable/c/f62c41b4910e65da396ec9a8c40c1fe7fe82e449