HIGH Introduced in 4.3
openvswitch ConnLabels UAF
CVE-2026-98251
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: openvswitch: avoid reallocating confirmed conntrack labels ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry does not have one. Confirmed conntracks can be read locklessly, so adding an extension may reallocate and free the extension block while another CPU accesses it. Only add the extension for unconfirmed conntracks. A confirmed conntrack without labels now fails the caller's label operation instead of reallocating its extension storage.
02KernelScan AI Analysis
Risk summary
A race condition in Open vSwitch conntrack label handling can cause use-after-free when network packets trigger label extension reallocation on confirmed conntrack entries that are being read locklessly by another CPU. An attacker sending traffic through an OVS bridge configured with conntrack label rules can exploit this to corrupt kernel memory, potentially leading to privilege escalation or denial of service. The bug requires OVS with conntrack label matching to be in use but needs no privileges from the attacker beyond sending network packets.
Vulnerability analysis
When Open vSwitch handles traffic using conntrack labels, it may add a labels extension to connection tracking entries that do not have one. Because confirmed connection tracking entries can be read concurrently by other processors without locking, adding that extension can reallocate and free memory while another processor is still reading it, causing a use-after-free. The fix prevents adding the extension to confirmed entries; instead, the label operation simply fails when a confirmed entry lacks labels. An attacker can reach the vulnerable code by sending network traffic through an Open vSwitch bridge that is configured to match or set conntrack labels, and no special privileges are needed beyond the ability to send that traffic.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 4.3 | 5.10.271 | 4371d79ea744 |
| 5.15 | 4.3 | 5.15.222 | 7ff688aceada |
| 6.1 | 4.3 | 6.1.189 | 05eab8dced6b |
| 6.6 | 4.3 | 6.6.158 | 579d87ec1e1e |
| 6.12 | 4.3 | 6.12.112 | 2e6dd889c325 |
| 6.18 | 4.3 | 6.18.54 | d16f089bd700 |
| 7.2 | 4.3 | 7.2.8 | 8c9fcc6c3395 |
| mainline | 4.3 | 7.3-rc4 | 3f118c8217c1 |