PatchSiren cyber security CVE debrief
CVE-2026-74347 Linux CVE debrief
A vulnerability in the Linux kernel's netfilter component has been addressed. The vulnerability relates to the handling of custom timeout policies for conntrack entries. The Linux kernel has been updated to properly manage the refcount of struct nf_ct_timeout, which is used to set custom timeout policies for conntrack entries. This update ensures that the ct timeout policy is released when it is no longer in use by any conntrack entry. The update also removes the refcount for the control plane, which controls if the ruleset refers to the timeout policy. This change simplifies the handling of timeout policies and prevents potential issues with refcounting.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-10-03
Who should care
Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should review and apply the updates to ensure the latest security patches are installed.
Why it matters
A vulnerability in the Linux kernel's netfilter component has been addressed, and updates are available to ensure proper management of custom timeout policies for conntrack entries. Linux kernel developers, maintainers, and users should review and apply the updates to prevent potential issues with refcounting and timeout policies.
- Verification of Linux kernel version and patch level is necessary to determine exposure.
- Review of conntrack entry and timeout policy configuration may be required to ensure proper functionality.
- Monitoring for potential issues with conntrack entries and timeout policies is recommended.
Technical summary
The Linux kernel vulnerability relates to the handling of custom timeout policies for conntrack entries in the netfilter component. The kernel has been updated to properly manage the refcount of struct nf_ct_timeout, ensuring that the ct timeout policy is released when it is no longer in use. This update simplifies the handling of timeout policies and prevents potential issues with refcounting. Linux kernel developers, maintainers, and users should review and apply the updates to prevent potential issues with refcounting and timeout policies. The vulnerability has been addressed in the Linux kernel, and updates are available to ensure proper management of custom timeout policies for conntrack entries.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the Linux kernel updates to ensure the latest security patches are installed.
- Verify that the Linux kernel version in use is not vulnerable to this issue.
- Monitor for any potential issues with conntrack entries and timeout policies.
- Perform a thorough review of the Linux kernel configuration and conntrack entry setup.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Consider implementing compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability. The Linux kernel source code changes are available on the kernel.org website. To verify exposure, Linux kernel developers and maintainers should review the Linux kernel version and patch level. Users of Linux-based systems should also verify their kernel version and apply updates as needed. The vulnerability affects the netfilter component of the Linux kernel, specifically the handling of custom timeout policies for conntrack entries. The Linux
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74347 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74347
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74347 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74347
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/44583fd5735cb0bdf3bfe11b1e51504ce387bdb7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7d6a9cdb8d3a51d9cfe546a09a518ab3d2671549
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9aeb0dcfeb460d33d61d434148b51103ab1d2013
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b2e84317f334d834fb06c9b340ea465f398b6d4f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.