PT-2026-79630 · Linux · Linux Kernel

CVE-2026-74625

·

Published

2026-08-22

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the netfilter bridge component where a bridge nftables ct zone set rule can attach a conntrack template to an skb (socket buffer) before the nf ct bridge pre() function processes it. For non-IPv4 and non-IPv6 EtherTypes, nf ct bridge pre() overwrites skb-> nfct with IP CT UNTRACKED without releasing the existing template reference. This leads to a memory leak of per-cpu templates and temporary templates allocated for concurrent use, which continues until the host exhausts its slab memory (a cache of commonly used kernel objects).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-97284
CVE-2026-74625

Affected Products

Linux Kernel