netfilter: nf_conncount: fix leaked ct in error paths
Summary
| CVE | CVE-2025-71146 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-01-23 15:16:05 UTC |
| Updated | 2026-07-30 06:24:54 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error paths There are some situations where ct might be leaked as error paths are skipping the refcounted check and return immediately. In order to solve it make sure that the check is always called. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.002390000 probability, percentile 0.150690000 (date 2026-08-01)
Problem Types: CWE-401
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Linux | Linux Kernel | 6.12.63 | All | All | All |
| Operating System | Linux | Linux Kernel | 6.18.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 6.19 | rc1 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 6e86f0eca857ee42787e30e9ec0b726aebfcae0a 08fa37f4c8c59c294e9c18fea2d083ee94074e5a git | Not specified |
| CNA | Linux | Linux | affected b160895d6bc9690459b16ef87799c9bd456af3ec e1ac8dce3a893641bef224ad057932f142b8a36f git | Not specified |
| CNA | Linux | Linux | affected 8d5a2c94c24dcc226863a7c2b5034750370c2189 f381a33f34dda9e4023e38ba68c943bca83245e9 git | Not specified |
| CNA | Linux | Linux | affected da9f247fb5efcd5a2730cdc989291b383c439e10 325eb61bb30790ea27782203a17b007ce1754a67 git | Not specified |
| CNA | Linux | Linux | affected 3558faee8aace3541189c3a2ca45c7e85e144b44 0b88be7211d21a0d68bb1e56dc805944e3654d6f git | Not specified |
| CNA | Linux | Linux | affected f6904ed15ed1a188543057e3cb0d02daa80edfc9 4bd2b89f4028f250dd1c1625eb3da1979b04a5e8 git | Not specified |
| CNA | Linux | Linux | affected be102eb6a0e7c03db00e50540622f4e43b2d2844 2e2a720766886190a6d35c116794693aabd332b6 git | Not specified |
| CNA | Linux | Linux | affected 8c2da7330214ce30f8333d1799a27ed0a9418f07 git | Not specified |
| CNA | Linux | Linux | affected 6.17.13 6.18 semver | Not specified |
| CNA | Linux | Linux | affected 6.12.63 6.12.64 semver | Not specified |
| CNA | Linux | Linux | affected 6.18.2 6.18.3 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/0b88be7211d21a0d68bb1e56dc805944e3654d6f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/2e2a720766886190a6d35c116794693aabd332b6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/f381a33f34dda9e4023e38ba68c943bca83245e9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/4bd2b89f4028f250dd1c1625eb3da1979b04a5e8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/e1ac8dce3a893641bef224ad057932f142b8a36f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/325eb61bb30790ea27782203a17b007ce1754a67 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/08fa37f4c8c59c294e9c18fea2d083ee94074e5a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.