PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74347 Linux CVE debrief

A vulnerability in the Linux kernel's netfilter component has been addressed. The vulnerability relates to the handling of custom timeout policies for conntrack entries. The Linux kernel has been updated to properly manage the refcount of struct nf_ct_timeout, which is used to set custom timeout policies for conntrack entries. This update ensures that the ct timeout policy is released when it is no longer in use by any conntrack entry. The update also removes the refcount for the control plane, which controls if the ruleset refers to the timeout policy. This change simplifies the handling of timeout policies and prevents potential issues with refcounting.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-10-03
Advisory published
2026-08-15
Advisory updated
2026-10-03

Who should care

Linux kernel developers and maintainers, Linux distribution maintainers, and users of Linux-based systems should review and apply the updates to ensure the latest security patches are installed.

Why it matters

A vulnerability in the Linux kernel's netfilter component has been addressed, and updates are available to ensure proper management of custom timeout policies for conntrack entries. Linux kernel developers, maintainers, and users should review and apply the updates to prevent potential issues with refcounting and timeout policies.

  • Verification of Linux kernel version and patch level is necessary to determine exposure.
  • Review of conntrack entry and timeout policy configuration may be required to ensure proper functionality.
  • Monitoring for potential issues with conntrack entries and timeout policies is recommended.

Technical summary

The Linux kernel vulnerability relates to the handling of custom timeout policies for conntrack entries in the netfilter component. The kernel has been updated to properly manage the refcount of struct nf_ct_timeout, ensuring that the ct timeout policy is released when it is no longer in use. This update simplifies the handling of timeout policies and prevents potential issues with refcounting. Linux kernel developers, maintainers, and users should review and apply the updates to prevent potential issues with refcounting and timeout policies. The vulnerability has been addressed in the Linux kernel, and updates are available to ensure proper management of custom timeout policies for conntrack entries.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the Linux kernel updates to ensure the latest security patches are installed.
  • Verify that the Linux kernel version in use is not vulnerable to this issue.
  • Monitor for any potential issues with conntrack entries and timeout policies.
  • Perform a thorough review of the Linux kernel configuration and conntrack entry setup.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Consider implementing compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability. The Linux kernel source code changes are available on the kernel.org website. To verify exposure, Linux kernel developers and maintainers should review the Linux kernel version and patch level. Users of Linux-based systems should also verify their kernel version and apply updates as needed. The vulnerability affects the netfilter component of the Linux kernel, specifically the handling of custom timeout policies for conntrack entries. The Linux

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74347 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74347

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74347 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74347

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/44583fd5735cb0bdf3bfe11b1e51504ce387bdb7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7d6a9cdb8d3a51d9cfe546a09a518ab3d2671549

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9aeb0dcfeb460d33d61d434148b51103ab1d2013

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b2e84317f334d834fb06c9b340ea465f398b6d4f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.