{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98251","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.331Z","datePublished":"2026-10-06T08:45:18.707Z","dateUpdated":"2026-10-07T06:49:38.707Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:38.707Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: avoid reallocating confirmed conntrack labels\n\novs_ct_get_conn_labels() adds the labels extension when a conntrack\nentry does not have one.  Confirmed conntracks can be read locklessly,\nso adding an extension may reallocate and free the extension block\nwhile another CPU accesses it.\n\nOnly add the extension for unconfirmed conntracks.  A confirmed\nconntrack without labels now fails the caller's label operation instead\nof reallocating its extension storage."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bad state is created by local setup over the OVS genetlink datapath/flow commands: a ct(commit,labels) action hits ovs_ct_commit()->ovs_ct_set_labels()->ovs_ct_get_conn_labels() on a confirmed conntrack created before labels_used was raised. Packets only trigger it; the cause is local flow and conntrack ordering.\nAC:L - The attacker creates the unlabelled confirmed conntrack (netfilter traffic before OVS init), installs the label flow, and sends both the triggering packet and the concurrent lockless ct->ext readers on other CPUs, so they control both sides of the krealloc race.\nPR:L - The OVS datapath/flow genl ops use GENL_UNS_ADMIN_PERM, so CAP_NET_ADMIN in a user-owned network namespace (unshare -Urn) is enough; real root is not needed.\nUI:N - No victim action is needed; the attacker sets up the flows and sends all the packets themselves.\nS:U - The corruption is in the kernel's own conntrack extension memory and the impact stays inside the kernel's authority; no VM or hardware boundary is crossed.\nC:H - nf_ct_ext_add() on a confirmed ct does krealloc(ct->ext) and frees the old extension block while other CPUs still dereference it locklessly. That is a slab use-after-free which can be reclaimed with attacker-sprayed data to leak kernel memory.\nI:H - Concurrent writers into the freed nf_ct_ext (labels, acct, ecache, helper data) write into reclaimed memory, a use-after-free write primitive that can be groomed to corrupt kernel objects.\nA:H - The use-after-free on ct->ext can oops the kernel, and WARN_ON(nf_ct_is_confirmed(ct)) in nf_ct_ext_add() panics hosts with panic_on_warn set."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/openvswitch/conntrack.c"],"versions":[{"version":"c2ac667358708d7cce64c78f58af6adf4c1e848b","lessThan":"4371d79ea74407fb992c985b1f94391e35bb8289","status":"affected","versionType":"git"},{"version":"c2ac667358708d7cce64c78f58af6adf4c1e848b","lessThan":"7ff688aceada1160331a789385ea146f62fbddf7","status":"affected","versionType":"git"},{"version":"c2ac667358708d7cce64c78f58af6adf4c1e848b","lessThan":"05eab8dced6bf4d3009a6eeee16ddac99047dc83","status":"affected","versionType":"git"},{"version":"c2ac667358708d7cce64c78f58af6adf4c1e848b","lessThan":"579d87ec1e1e85729a6cb2c25961e58beb78640c","status":"affected","versionType":"git"},{"version":"c2ac667358708d7cce64c78f58af6adf4c1e848b","lessThan":"2e6dd889c325abf23821e1459c3ffef59b7f0009","status":"affected","versionType":"git"},{"version":"c2ac667358708d7cce64c78f58af6adf4c1e848b","lessThan":"d16f089bd700f45d720ce989d5495e1dc3be0cf8","status":"affected","versionType":"git"},{"version":"c2ac667358708d7cce64c78f58af6adf4c1e848b","lessThan":"8c9fcc6c33950d3db551af664d1fd3d998bfee56","status":"affected","versionType":"git"},{"version":"c2ac667358708d7cce64c78f58af6adf4c1e848b","lessThan":"3f118c8217c109fd13ca61caa301d72c483897ef","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/openvswitch/conntrack.c"],"versions":[{"version":"4.3","status":"affected"},{"version":"0","lessThan":"4.3","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4371d79ea74407fb992c985b1f94391e35bb8289"},{"url":"https://git.kernel.org/stable/c/7ff688aceada1160331a789385ea146f62fbddf7"},{"url":"https://git.kernel.org/stable/c/05eab8dced6bf4d3009a6eeee16ddac99047dc83"},{"url":"https://git.kernel.org/stable/c/579d87ec1e1e85729a6cb2c25961e58beb78640c"},{"url":"https://git.kernel.org/stable/c/2e6dd889c325abf23821e1459c3ffef59b7f0009"},{"url":"https://git.kernel.org/stable/c/d16f089bd700f45d720ce989d5495e1dc3be0cf8"},{"url":"https://git.kernel.org/stable/c/8c9fcc6c33950d3db551af664d1fd3d998bfee56"},{"url":"https://git.kernel.org/stable/c/3f118c8217c109fd13ca61caa301d72c483897ef"}],"title":"openvswitch: avoid reallocating confirmed conntrack labels","x_generator":{"engine":"bippy-1.2.0"}}}}