CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72423

highCVSS 8.8covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: bpf: Guard conntrack opts error writes The conntrack lookup and allocation kfuncs take an opts pointer together with an optssz argument. The verifier checks only the memory range described by optssz, but the wrappers unconditionally write opts->error whenever the internal lookup or allocation helper returns an error. For an invalid size smaller than the end of opts->error, that write can land outside the verifier-checked range. Keep returning NULL for invalid arguments, but only report the error through opts->error when the supplied size includes the field. This preserves error reporting for the supported 12-byte and 16-byte layouts, and for other invalid sizes that still include opts->error.

CSIRTS triage

What
BPF engine guards writes to conntrack options error paths to prevent unsafe memory access.
Who is affected
Linux systems with BPF conntrack offloading enabled.
Urgency
Medium urgency; unguarded error writes could lead to memory corruption via BPF programs.
Action
Apply kernel patch that guards conntrack options error writes.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-72423

Get an email if CVE-2026-72423 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-72423

CVE.org record

Embed the live status

CVE-2026-72423 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-72423 status](https://www.csirts.com/badge/CVE-2026-72423)](https://www.csirts.com/cve/CVE-2026-72423)