CVE-2026-43060

Updated on 05 May 2026

Severity

7.8 High severity

Details

CVSS score
7.8
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_ct: drop pending enqueued packets on removal

Packets sitting in nfqueue might hold a reference to:

  • templates that specify the conntrack zone, because a percpu area is used and module removal is possible.
  • conntrack timeout policies and helper, where object removal leave a stale reference.

Since these objects can just go away, drop enqueued packets to avoid stale reference to them.

If there is a need for finer grain removal, this logic can be revisited to make selective packet drop upon dependencies.

Details

Affected product:
Ubuntu 20.04 ELS
Affected packages:
linux @ 5.4.0 (+1 more)

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Amazon Linux 2023 Planned
Debian 11 Planned
Debian 11 cloud Planned
Debian 13 Planned
Ubuntu 22.04 Planned
Ubuntu 24.04 Planned