KernelScan.io

HIGH Introduced in 5.18

netfilter CtOpts OOB

CVE-2026-72423

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

KernelScan AI7.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: bpf: Guard conntrack opts error writes The conntrack lookup and allocation kfuncs take an opts pointer together with an opts__sz argument. The verifier checks only the memory range described by opts__sz, but the wrappers unconditionally write opts->error whenever the internal lookup or allocation helper returns an error. For an invalid size smaller than the end of opts->error, that write can land outside the verifier-checked range. Keep returning NULL for invalid arguments, but only report the error through opts->error when the supplied size includes the field. This preserves error reporting for the supported 12-byte and 16-byte layouts, and for other invalid sizes that still include opts->error.

02

Engine v0.6.0

Risk summary

A local user who can load BPF programs can exploit an out-of-bounds write in the conntrack kfunc wrappers to write beyond the verifier-approved memory range, potentially corrupting adjacent BPF stack or map memory. This bypasses BPF verifier safety guarantees and can lead to arbitrary kernel read/write, privilege escalation, or denial of service. Products that allow unprivileged BPF or expose BPF loading to tenants are at highest risk.

Affectednet/netfilter/nf_conntrack_bpf.c (BPF conntrack kfuncs)

Vulnerability analysis

When a BPF program calls the kernel's conntrack lookup or allocation helpers, it passes an options buffer and tells the kernel how large it is. The kernel's safety checker only permits access within that declared size, but the helpers always attempt to store an error code beyond that boundary whenever the lookup fails. If the declared size is smaller than where that error value sits, the write escapes the approved region and corrupts nearby memory that the checker never authorized. This breaks the BPF sandbox and can damage adjacent program data, creating a path to arbitrary kernel memory access. The corrected code now only records the error when the supplied size actually covers the error field, so undersized buffers no longer receive stray writes. A local user who can load BPF programs — requiring CAP_BPF, which an unprivileged process can hold inside a user namespace when that feature is enabled — can trigger this by forcing one of those helpers to fail with a deliberately undersized options buffer.

03

BranchIntroducedFixed inPatch commit
mainline5.187.2-rc16f6183a39533
7.15.187.1.5dd74c8020384