netfilter: bridge: release template ct on non-IP path

Summary

CVECVE-2026-74625
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-22 16:16:35 UTC
Updated2026-08-22 16:16:35 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: release template ct on non-IP path A bridge nftables ct zone set rule can attach a conntrack template to an skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6 EtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with IP_CT_UNTRACKED without releasing the existing template reference. That makes the per-cpu template, and any temporary templates allocated for concurrent use, unreachable and leaks memory until the host runs out of slab. Reset the skb conntrack state before marking the frame untracked so the existing template reference is dropped on the non-IP path.

Risk And Classification

EPSS: 0.002200000 probability, percentile 0.127460000 (date 2026-08-23)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 3c171f496ef57774f8e5d509923372549734877f fc90df37540627d092af770215fb4b7befe9409b git Not specified
CNA Linux Linux affected 3c171f496ef57774f8e5d509923372549734877f daa6e070f8e1e7a4dddec8b64ca37663f8cda917 git Not specified
CNA Linux Linux affected 3c171f496ef57774f8e5d509923372549734877f bd7b16494dacf87e9336a1dcfdada83b9e40edd6 git Not specified
CNA Linux Linux affected 3c171f496ef57774f8e5d509923372549734877f 6ea88401e10e04e0b3bb7a7adea54932fb60b93b git Not specified
CNA Linux Linux affected 3c171f496ef57774f8e5d509923372549734877f 46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd git Not specified
CNA Linux Linux affected 3c171f496ef57774f8e5d509923372549734877f c58d34fe8b7e47bb0b350a7625023b1261342be5 git Not specified
CNA Linux Linux affected 3c171f496ef57774f8e5d509923372549734877f 7cff440d702616022769f2643168d7f9820547a0 git Not specified
CNA Linux Linux affected 3c171f496ef57774f8e5d509923372549734877f d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f git Not specified
CNA Linux Linux affected 5.3 Not specified
CNA Linux Linux unaffected 5.3 semver Not specified
CNA Linux Linux unaffected 5.10.265 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.216 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.183 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.152 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.104 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.45 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.9 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/fc90df37540627d092af770215fb4b7befe9409b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6ea88401e10e04e0b3bb7a7adea54932fb60b93b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bd7b16494dacf87e9336a1dcfdada83b9e40edd6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c58d34fe8b7e47bb0b350a7625023b1261342be5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7cff440d702616022769f2643168d7f9820547a0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/daa6e070f8e1e7a4dddec8b64ca37663f8cda917 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report