{"id":"CVE-2026-74625","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74625","summary":"netfilter: bridge: release template ct on non-IP path","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: release template ct on non-IP path\n\nA bridge nftables ct zone set rule can attach a conntrack template to\nan skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6\nEtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with\nIP_CT_UNTRACKED without releasing the existing template reference.\n\nThat makes the per-cpu template, and any temporary templates allocated\nfor concurrent use, unreachable and leaks memory until the host runs out\nof slab.\n\nReset the skb conntrack state before marking the frame untracked so the\nexisting template reference is dropped on the non-IP path.","published":"2026-08-22T15:32:07.929Z","modified":"2026-08-24T11:47:03.825292386Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"5.10.265"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6ea88401e10e04e0b3bb7a7adea54932fb60b93b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7cff440d702616022769f2643168d7f9820547a0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bd7b16494dacf87e9336a1dcfdada83b9e40edd6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c58d34fe8b7e47bb0b350a7625023b1261342be5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/daa6e070f8e1e7a4dddec8b64ca37663f8cda917"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fc90df37540627d092af770215fb4b7befe9409b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74625.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74625"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T11:47:03.825292386Z"}}