KernelScan.io

HIGH Introduced in 4.3

openvswitch ConnLabels UAF

CVE-2026-98251

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: openvswitch: avoid reallocating confirmed conntrack labels ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry does not have one. Confirmed conntracks can be read locklessly, so adding an extension may reallocate and free the extension block while another CPU accesses it. Only add the extension for unconfirmed conntracks. A confirmed conntrack without labels now fails the caller's label operation instead of reallocating its extension storage.

02

Engine v0.7.0

Risk summary

A race condition in Open vSwitch conntrack label handling can cause use-after-free when network packets trigger label extension reallocation on confirmed conntrack entries that are being read locklessly by another CPU. An attacker sending traffic through an OVS bridge configured with conntrack label rules can exploit this to corrupt kernel memory, potentially leading to privilege escalation or denial of service. The bug requires OVS with conntrack label matching to be in use but needs no privileges from the attacker beyond sending network packets.

Affectednet/openvswitch/conntrack.c (openvswitch)

Vulnerability analysis

When Open vSwitch handles traffic using conntrack labels, it may add a labels extension to connection tracking entries that do not have one. Because confirmed connection tracking entries can be read concurrently by other processors without locking, adding that extension can reallocate and free memory while another processor is still reading it, causing a use-after-free. The fix prevents adding the extension to confirmed entries; instead, the label operation simply fails when a confirmed entry lacks labels. An attacker can reach the vulnerable code by sending network traffic through an Open vSwitch bridge that is configured to match or set conntrack labels, and no special privileges are needed beyond the ability to send that traffic.

03

BranchIntroducedFixed inPatch commit
5.104.35.10.2714371d79ea744
5.154.35.15.2227ff688aceada
6.14.36.1.18905eab8dced6b
6.64.36.6.158579d87ec1e1e
6.124.36.12.1122e6dd889c325
6.184.36.18.54d16f089bd700
7.24.37.2.88c9fcc6c3395
mainline4.37.3-rc43f118c8217c1