CVE-2025-71146
MEDIUMLinux Kernel - Use-After-Free in netfilter nf_conncount Error Paths
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error paths There are some situations where ct might be leaked as error paths are skipping the refcounted check and return immediately. In order to solve it make sure that the check is always called.
References (7)
Core 7
Core References
Scores
CVSS v3
5.5
EPSS
0.0011
EPSS Percentile
1.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-401
Status
published
Products (17)
linux/Kernel
6.12.63 - 6.12.64linux
linux/Kernel
6.18.2 - 6.18.3linux
Linux/Linux
3558faee8aace3541189c3a2ca45c7e85e144b44 - 0b88be7211d21a0d68bb1e56dc805944e3654d6f
Linux/Linux
6.12.63 - 6.12.64
Linux/Linux
6.17.13 - 6.18
Linux/Linux
6.18.2 - 6.18.3
Linux/Linux
6e86f0eca857ee42787e30e9ec0b726aebfcae0a - 08fa37f4c8c59c294e9c18fea2d083ee94074e5a
Linux/Linux
8c2da7330214ce30f8333d1799a27ed0a9418f07
Linux/Linux
8d5a2c94c24dcc226863a7c2b5034750370c2189 - f381a33f34dda9e4023e38ba68c943bca83245e9
Linux/Linux
b160895d6bc9690459b16ef87799c9bd456af3ec - e1ac8dce3a893641bef224ad057932f142b8a36f
... and 7 more
Published
Jan 23, 2026
Tracked Since
Feb 18, 2026