{"id":"CVE-2026-72057","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72057","summary":"net/sched: act_ct: preserve tc_skb_cb across defragmentation","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: preserve tc_skb_cb across defragmentation\n\ntcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving\nand restoring skb->cb. The defrag helper clears IPCB/IP6CB, which aliases\nthe tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through\nact_ct therefore loses qdisc metadata such as pkt_segs and can trigger\nWARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabled.\n\nSave and restore the full tc_skb_cb around nf_ct_handle_fragments(),\nmatching the pattern used by ovs_ct_handle_fragments().","published":"2026-08-15T05:52:12.873Z","modified":"2026-08-16T03:48:31.472162846Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.6.145"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2400c4b05d58834b994500a9eec90a37db44187c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5c3ae5f6c7c6de73ea9b6a75154fe4ed343e1bac"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9092e15defbe6c7bc241c306093ca9d358a578e7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b3d835407846134b0d54637c0281b39bebef831d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f7f45ceb855d9ba1cba594fb3f383255f7013fad"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72057.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72057"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-16T03:48:31.472162846Z"}}