CVE-2026-72430
Last modified
CVE-2026-72430 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix nf_connlabels leak on two error paths tcf_ct_fill_params() calls nf_connlabels_get() (setting put_labels) when TCA_CT_LABELS is present, but two later error sites use a bare return instead of "goto err", skipping the err: nf_connlabels_put() cleanup. They also precede the "p->put_labels = put_labels" assignment, so the tcf_ct_params_free() fallback does not release the count either. Each failed RTM_NEWACTION on these paths leaks one nf_connlabels reference: net->ct.labels_used is incremented and never released. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix nf_connlabels leak on two error paths tcf_ct_fill_params() calls nf_connlabels_get() (setting put_labels) when TCA_CT_LABELS is present, but two later error sites use a bare return instead of "goto err", skipping the err: nf_connlabels_put() cleanup. They also precede the "p->put_labels = put_labels" assignment, so the tcf_ct_params_free() fallback does not release the count either. Each failed RTM_NEWACTION on these paths leaks one nf_connlabels reference: net->ct.labels_used is incremented and never released. The action is reachable with CAP_NET_ADMIN over the netns, i.e. from an unprivileged user namespace on default-userns kernels. Impact: an unprivileged user with CAP_NET_ADMIN over a network namespace (e.g. via user namespaces) leaks one nf_connlabels reference per failed RTM_NEWACTION on the two error paths; net->ct.labels_used is never released. The err: label is safe to reach from both sites: p->tmpl is still NULL there (kzalloc'd, not yet assigned) and nf_ct_put(NULL) is a no-op, so no inline release is needed.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 70f06c115bcca26ceeebf938e48bc8143668e38b, < 13b561c893c741635adce3781490a7a1099106c8; >= 70f06c115bcca26ceeebf938e48bc8143668e38b, < 1d51aff78f078af1a80e9496c2f4643f4c0ef0a0; >= 70f06c115bcca26ceeebf938e48bc8143668e38b, < 0c3d8fc87e10e38fe054ece009d6d1f66bef2cd4; >= 70f06c115bcca26ceeebf938e48bc8143668e38b, < 16e088016f38cf728a0de709c3335cc5a3850476 |
| Linux | Linux | 6.7 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72430?
How severe is CVE-2026-72430?
How do I fix CVE-2026-72430?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72425In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-72426In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-72427In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72428In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72429In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-7243A vulnerability was identified in Totolink A8000RU 7.1cu.643…9.8
- CVE-2026-72431In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72432In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72433In the Linux kernel, the following vulnerability has been re…
- CVE-2026-72434In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72435In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-72436In the Linux kernel, the following vulnerability has been re…9.8
Are you affected by CVE-2026-72430?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
