PT-2026-37426 · Linux+1 · Linux Kernel+1

CVE-2026-43116

·

Published

2026-05-06

·

Updated

2026-08-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw in the netfilter ctnetlink component allows for unsafe access to the master conntrack object. Holding a reference to the expectation is insufficient because the master conntrack object can be removed, rendering exp->master invalid. This occurs during the delete expectation command, the get expectation command, and during the delivery of the IPEXP NEW event, where the master conntrack event cache is accessed via exp->master.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21557
ALSA-2026:25217
ALSA-2026:49213
ALSA-2026:49214
AZL-85851
CVE-2026-43116
ECHO-F074-174B-4938
OESA-2026-2674
OESA-2026-2869
OESA-2026-3157
RHSA-2026:21557
RHSA-2026:25217
RHSA-2026:26462
RHSA-2026:26515
RHSA-2026:26535
RHSA-2026:26563
RHSA-2026:26570
RHSA-2026:27708
RHSA-2026:27731
RHSA-2026:27735

Affected Products

Linux Kernel
Rocky Linux