{"apiVersion":"1.0","identifier":"CVE-2026-72418","description":"In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: prevent connlimit drops for early confirmed ct Commit 69894e5b4c5e (-netfilter: nft_connlimit: update the count if add was skipped-) introduced a regression where packets for valid connections are dropped when using connlimit for soft-limiting scenarios. The issue occurs when a new connection reuses a socket currently in the TIME_WAIT state. In this scenario, the connection tracking entry is evaluated as already confirmed. Previously, __nf_conncount_add() assumed that if a connection was confirmed and did not originate from the loopback interface, it should skip the addition and return -EEXIST. Skipping the addition triggers a garbage collection run that cleans up the TIME_WAIT connection. Consequently, the active connection count drops to 0, which xt_connlimit mishandles, leading to the false rejection of the perfectly valid new connection. Fix this by replacing the interface check with protocol-agnostic state checks. We now skip the tree insertion and preserve the lockless garbage collection optimization only if the connection is IPS_ASSURED. This allows early-confirmed setup packets (such as reused TIME_WAIT sockets or locally generated SYN-ACKs) to be properly evaluated and counted without falsely dropping. The goto check_connections path is maintained to ensure these setup packets are deduplicated correctly. This has been tested with slowhttptest and HTTP server configured locally to ensure we are not breaking soft-limiting scenarios for local or external connections. In addition, it was tested with a OVS zone limit too.","publishedAt":"2026-08-15T06:22:15","lastModifiedAt":"2026-08-17T06:19:08","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72418","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00707,"riskScore":0.8,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72418","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72418","en":"https://www.redsauce.net/en/cves/CVE-2026-72418","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72418","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72418","de":"https://www.redsauce.net/de/cves/CVE-2026-72418","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72418","el":"https://www.redsauce.net/el/cves/CVE-2026-72418"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72418"}}