netfilter: nft_ct: fix missing expect put in obj eval

Summary

CVECVE-2026-52970
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-06-24 17:17:07 UTC
Updated2026-06-24 17:17:07 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix missing expect put in obj eval nft_ct_expect_obj_eval() allocates an expectation and may call nf_ct_expect_related(), but never drops its local reference. Add nf_ct_expect_put(exp) before return to balance allocation.

Risk And Classification

EPSS: 0.001840000 probability, percentile 0.082040000 (date 2026-06-26)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 857b46027d6f91150797295752581b7155b9d0e1 cdb9a25dd3416d427e8b2753210f8baf44207577 git Not specified
CNA Linux Linux affected 857b46027d6f91150797295752581b7155b9d0e1 26ab32ec73941871c97562ee1f39587950dc3b68 git Not specified
CNA Linux Linux affected 857b46027d6f91150797295752581b7155b9d0e1 7b96242ceedfe249f158419f3254bcee04173ffe git Not specified
CNA Linux Linux affected 857b46027d6f91150797295752581b7155b9d0e1 ecca618e1e339494911090474ed87742c0f73976 git Not specified
CNA Linux Linux affected 857b46027d6f91150797295752581b7155b9d0e1 2aef1b13d5c0285f340512c6c07eb858fd018fd8 git Not specified
CNA Linux Linux affected 857b46027d6f91150797295752581b7155b9d0e1 1dced0725e2fae3ac3416274db20a7ff5a46931d git Not specified
CNA Linux Linux affected 857b46027d6f91150797295752581b7155b9d0e1 84c422cea5a45fe56be839f25880f21fd33940cd git Not specified
CNA Linux Linux affected 857b46027d6f91150797295752581b7155b9d0e1 19f94b6fee75b3ef7fbc06f3745b9a771a8a19a4 git Not specified
CNA Linux Linux affected 5.3 Not specified
CNA Linux Linux unaffected 5.3 semver Not specified
CNA Linux Linux unaffected 5.10.258 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.209 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.175 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.141 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.91 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.33 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.10 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/2aef1b13d5c0285f340512c6c07eb858fd018fd8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/84c422cea5a45fe56be839f25880f21fd33940cd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/26ab32ec73941871c97562ee1f39587950dc3b68 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/cdb9a25dd3416d427e8b2753210f8baf44207577 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/19f94b6fee75b3ef7fbc06f3745b9a771a8a19a4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ecca618e1e339494911090474ed87742c0f73976 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1dced0725e2fae3ac3416274db20a7ff5a46931d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7b96242ceedfe249f158419f3254bcee04173ffe 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report