ACK: [SRU][J][PATCH 0/1] CVE-2026-31414
Kuba Pawlak
kuba.pawlak at canonical.com
Thu Jun 25 10:10:55 UTC 2026
On 6/24/26 02:38, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2026-31414
>
> [ Impact ]
>
> The netfilter connection tracking expectation code in ctnetlink and /proc dumps
> the helper name using nfct_help() without holding a reference to the master
> conntrack. Accessing the helper this way is unsafe and can lead to a use-after-
> free condition when the master conntrack is freed concurrently. This is
> remotely exploitable and carries a CVSS score of 9.8, potentially allowing
> memory corruption or privilege escalation.
>
> [ Fix ]
>
> jammy: backported with AI-assisted adaptation
> bionic: backported with AI-assisted adaptation
> trusty: backported with AI-assisted adaptation
>
> [ Test Plan ]
>
> Boot tested.
>
> [ Where Problems Could Occur ]
>
> A regression in this change would affect the netfilter nf_conntrack_expect
> subsystem, potentially causing incorrect helper names to be reported in
> ctnetlink or /proc output, or affecting expectation creation behaviour when
> userspace does not supply an explicit helper.
>
Acked-by: Kuba Pawlak <kuba.pawlak at canonical.com>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_0x216A9D7E3B63DCB4.asc
Type: application/pgp-keys
Size: 3139 bytes
Desc: OpenPGP public key
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260625/d71e992d/attachment-0001.key>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260625/d71e992d/attachment-0001.sig>
More information about the kernel-team
mailing list