← All Advisories

CVE-2026-74347

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-74347

Key Details

CVECVE-2026-74347
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount

Add a refcount for struct nf_ct_timeout which is used by ct extension to

set the custom ct timeout policy, this tells us that the ct timeout is

being used by a conntrack entry. When the last conntrack entry drops the

refcount on the ct timeout, the ct timeout is released.

Remove the refcount for control plane which controls if the ruleset

refers to the timeout policy. After this update, it is possible to

remove the ct timeout policy from nfnetlink_cttimeout immediately.

This is for simplicity not to handle two refcounts on a single object.

Remove nf_queue_nf_hook_drop(): a packet sitting in nfqueue will just

hold a reference to the nf_ct_timeout object until packet is reinjected,

since this is part of the ct extension, this will be released by the

time the conntrack is freed.

nf_ct_untimeout() is still called to clean up in a best effort basis:

the ct timeout on existing entries gets removed when the ct timeout goes

away, but as long as the iptables ruleset still refers to the ct timeout

through a template, new conntracks may keep attaching it and extend its

lifetime until the rule is removed.

nf_ct_untimeout() is not called anymore from module removal path, this

is unlikely to find timeouts give module refcount is bumped, and the new

refcount already tracks the ct timeout policy use so it is released when

unused. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74347
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74347