PT-2026-52362 · Linux+1 · Linux Kernel+1

CVE-2026-53267

·

Published

2026-06-25

·

Updated

2026-09-09

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description An issue exists in the netfilter nft ct component where the system fails to properly handle template connection tracking (ct) during evaluation. When a rule sets a connection tracking zone via nft ct set zone eval(), a per-cpu template ct is attached. A subsequent call to nft ct get eval() may treat this template as a real connection tracking entry, leading to a 16-byte memory copy. Depending on the destination register value, this can result in a stack overflow past struct nft regs or the silent corruption of adjacent registers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90947
CVE-2026-53267
ECHO-8802-63A7-463D
OESA-2026-3204
OESA-2026-3206
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3593-1
SUSE-SU-2026:3594-1
SUSE-SU-2026:3595-1
SUSE-SU-2026:3602-1
SUSE-SU-2026:3616-1
SUSE-SU-2026:3617-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu