๐Ÿ” CVE Alert

CVE-2026-72430

UNKNOWN 0.0

net/sched: act_ct: fix nf_connlabels leak on two error paths

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix nf_connlabels leak on two error paths tcf_ct_fill_params() calls nf_connlabels_get() (setting put_labels) when TCA_CT_LABELS is present, but two later error sites use a bare return instead of "goto err", skipping the err: nf_connlabels_put() cleanup. They also precede the "p->put_labels = put_labels" assignment, so the tcf_ct_params_free() fallback does not release the count either. Each failed RTM_NEWACTION on these paths leaks one nf_connlabels reference: net->ct.labels_used is incremented and never released. The action is reachable with CAP_NET_ADMIN over the netns, i.e. from an unprivileged user namespace on default-userns kernels. Impact: an unprivileged user with CAP_NET_ADMIN over a network namespace (e.g. via user namespaces) leaks one nf_connlabels reference per failed RTM_NEWACTION on the two error paths; net->ct.labels_used is never released. The err: label is safe to reach from both sites: p->tmpl is still NULL there (kzalloc'd, not yet assigned) and nf_ct_put(NULL) is a no-op, so no inline release is needed.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
70f06c115bcca26ceeebf938e48bc8143668e38b < 13b561c893c741635adce3781490a7a1099106c8 70f06c115bcca26ceeebf938e48bc8143668e38b < 1d51aff78f078af1a80e9496c2f4643f4c0ef0a0 70f06c115bcca26ceeebf938e48bc8143668e38b < 0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4 70f06c115bcca26ceeebf938e48bc8143668e38b < 16e088016f38cf728a0de709c3335cc5a3850476
Linux / Linux
6.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/13b561c893c741635adce3781490a7a1099106c8 git.kernel.org: https://git.kernel.org/stable/c/1d51aff78f078af1a80e9496c2f4643f4c0ef0a0 git.kernel.org: https://git.kernel.org/stable/c/0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4 git.kernel.org: https://git.kernel.org/stable/c/16e088016f38cf728a0de709c3335cc5a3850476