CVE-2026-45860 Details
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection clean up limit to 64 After the optimization to only perform one GC per jiffy, a new problem was introduced. If more than 8 new connections are tracked per jiffy the list won't be cleaned up fast enough possibly reaching the limit wrongly. In order to prevent this issue, only skip the GC if it was already triggered during the same jiffy and the increment is lower than the clean up limit. In addition, increase the clean up limit to 64 connections to avoid triggering GC too often and do more effective GCs. This has been tested using a HTTP server and several performance tools while having nft_connlimit/xt_connlimit or OVS limit configured. Output of slowhttptest + OVS limit at 52000 connections: slow HTTP test status on 340th second: initializing: 0 pending: 432 connected: 51998 error: 0 closed: 0 service available: YES
A vulnerability in the Linux kernel's netfilter component, specifically within the nf_conncount module, has been addressed. This issue arose after an optimization that reduced garbage collection (GC) frequency, which inadvertently caused connection tracking to exceed the cleanup capacity. The vulnerability could lead to improper management of connection data, potentially disrupting network operations.
Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for updating the kernel can be found in the official Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0792ad077d776c2dcf20f0484e2461ded1b77a24 | kernel.org | Patch |
| https://git.kernel.org/stable/c/0af0812baf2d363176c9b76fc07e33f13aede8db | kernel.org | Patch |
| https://git.kernel.org/stable/c/13eede458fdf231f1bf96a398feea4ad1553f14c | kernel.org | Patch |
| https://git.kernel.org/stable/c/21d033e472735ecec677f1ae46d6740b5e47a4f3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3d0994ed0aa1fc0a2c5e620b765e8defdd021bff | kernel.org | Patch |
| https://git.kernel.org/stable/c/6e5fa7add3e76da068a478d905be64be8fa4e80a | kernel.org | Patch |
| https://git.kernel.org/stable/c/a5c9e14e0e8923218ae881d5e78c990c07694966 | kernel.org | Patch |
| https://git.kernel.org/stable/c/fa85432d58c8e74b39333edbf8d28df2985dfc79 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.10.248, < 5.10.252 >= 5.15.198, < 5.15.202 >= 5.19, < 6.1.165 >= 6.2, < 6.6.128 >= 6.7, < 6.12.75 >= 6.13, < 6.18.14 >= 6.19, < 6.19.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 30, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |