All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-72247: netfilter: nf_conncount: fix zone comparison in tuple dedup
Date: Sat, 15 Aug 2026 15:05:26 +0900	[thread overview]
Message-ID: <2026081552-CVE-2026-72247-73b5@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conncount: fix zone comparison in tuple dedup

The "already exists" dedup logic in __nf_conncount_add() decides
whether a connection has already been counted and can be skipped instead
of incrementing the connlimit count.  It compares the conntrack zone of a
list entry with the zone of the connection being added using
nf_ct_zone_id() and nf_ct_zone_equal(), passing conn->zone.dir or
zone->dir as the direction argument.

Those helpers take enum ip_conntrack_dir values: IP_CT_DIR_ORIGINAL is 0
and IP_CT_DIR_REPLY is 1.  However, zone->dir is a u8 bitmask:
NF_CT_ZONE_DIR_ORIG is 1, NF_CT_ZONE_DIR_REPL is 2 and
NF_CT_DEFAULT_ZONE_DIR is 3.  Passing that bitmask as the enum direction
shifts the meaning of every non-zero value.  An ORIG-only zone passes 1
and is tested as REPLY, while REPL-only and default zones pass 2 or 3 and
test bits beyond the valid direction range.  In those cases
nf_ct_zone_id() can fall back to NF_CT_DEFAULT_ZONE_ID instead of using
the real zone id, so different zones can be treated as equal and dedup
collapses to tuple equality alone.

nf_conncount stores and compares the original-direction tuple for a
connection.  If an skb already has an attached conntrack entry,
get_ct_or_tuple_from_skb() explicitly copies
ct->tuplehash[IP_CT_DIR_ORIGINAL].tuple, regardless of the packet's
ctinfo.  Therefore the zone comparison in the tuple dedup path must use
IP_CT_DIR_ORIGINAL as well; the zone direction bitmask describes where a
zone id applies, not which direction this conncount tuple represents.

Fix the two dedup comparisons by passing IP_CT_DIR_ORIGINAL directly.
Do not special-case NF_CT_DEFAULT_ZONE_DIR and do not compare raw zone
ids: using the existing helpers with IP_CT_DIR_ORIGINAL preserves the
direction-aware NF_CT_DEFAULT_ZONE_ID fallback.  A default bidirectional
zone contains the ORIG bit, so it naturally returns the real zone id;
reply-only zones continue to fall back for original-direction tuple
comparisons.

The Linux kernel CVE team has assigned CVE-2026-72247 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.18 with commit 21ba8847f857028dc83a0f341e16ecc616e34740 and fixed in 5.10.261 with commit 82fc35e0da9a91db9a034f8311f18f77a599ae3f
	Issue introduced in 4.18 with commit 21ba8847f857028dc83a0f341e16ecc616e34740 and fixed in 5.15.212 with commit 78b5d6dbc860776161f9e9206b06ff8a01f531ab
	Issue introduced in 4.18 with commit 21ba8847f857028dc83a0f341e16ecc616e34740 and fixed in 6.1.178 with commit 4f30a89c0ed2418719a1144881c2635b940b543d
	Issue introduced in 4.18 with commit 21ba8847f857028dc83a0f341e16ecc616e34740 and fixed in 6.6.145 with commit 7bdc3c0985ecf17b957811fedcc684acdf698acc
	Issue introduced in 4.18 with commit 21ba8847f857028dc83a0f341e16ecc616e34740 and fixed in 6.12.97 with commit 35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce
	Issue introduced in 4.18 with commit 21ba8847f857028dc83a0f341e16ecc616e34740 and fixed in 6.18.40 with commit 3cd9a5792cbea81139c24320986dd0db69e9b5d0
	Issue introduced in 4.18 with commit 21ba8847f857028dc83a0f341e16ecc616e34740 and fixed in 7.1.5 with commit 6ff07ac5405bea4d4ead3559fc123f987576424a
	Issue introduced in 4.18 with commit 21ba8847f857028dc83a0f341e16ecc616e34740 and fixed in 7.2-rc4 with commit f62c41b4910e65da396ec9a8c40c1fe7fe82e449
	Issue introduced in 4.14.92 with commit 525e1dffed8711973f77412729621098a95238e5
	Issue introduced in 4.14.92 with commit 75af3d78168e654a5cd8bbc4c774f97be836165f

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72247
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/netfilter/nf_conncount.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/82fc35e0da9a91db9a034f8311f18f77a599ae3f
	https://git.kernel.org/stable/c/78b5d6dbc860776161f9e9206b06ff8a01f531ab
	https://git.kernel.org/stable/c/4f30a89c0ed2418719a1144881c2635b940b543d
	https://git.kernel.org/stable/c/7bdc3c0985ecf17b957811fedcc684acdf698acc
	https://git.kernel.org/stable/c/35a56e2a46b90e6bd4ca816b80e9cb8d20dfc3ce
	https://git.kernel.org/stable/c/3cd9a5792cbea81139c24320986dd0db69e9b5d0
	https://git.kernel.org/stable/c/6ff07ac5405bea4d4ead3559fc123f987576424a
	https://git.kernel.org/stable/c/f62c41b4910e65da396ec9a8c40c1fe7fe82e449

                 reply	other threads:[~2026-08-15  6:18 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026081552-CVE-2026-72247-73b5@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.