Race condition in Linux kernel - CVE-2026-80668
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in nf_conntrack expectation handling when removing or expiring expectations. A local user can trigger concurrent expectation operations to cause a denial of service.
The issue involves an expectation accessing a stale exp->master pointer after the associated master connection has already been released.