cbcvebase.
CVE-2025-71146
published 2026-01-23

CVE-2025-71146: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error paths There are some situations where ct…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error paths There are some situations where ct might be leaked as error paths are skipping the refcounted check and return immediately. In order to solve it make sure that the check is always called.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.3-1 (forky)linux 6.18.3-1 (forky)
linuxlinux
linuxlinux>= 3558faee8aace3541189c3a2ca45c7e85e144b44 < 0b88be7211d21a0d68bb1e56dc805944e3654d6f0b88be7211d21a0d68bb1e56dc805944e3654d6f
linuxlinux>= 6.12.63 < 6.12.646.12.64
linuxlinux>= 6.17.13 < 6.186.18
linuxlinux>= 6.18.2 < 6.18.36.18.3
linuxlinux>= 6e86f0eca857ee42787e30e9ec0b726aebfcae0a < 08fa37f4c8c59c294e9c18fea2d083ee94074e5a08fa37f4c8c59c294e9c18fea2d083ee94074e5a
linuxlinux>= 8d5a2c94c24dcc226863a7c2b5034750370c2189 < f381a33f34dda9e4023e38ba68c943bca83245e9f381a33f34dda9e4023e38ba68c943bca83245e9
linuxlinux>= b160895d6bc9690459b16ef87799c9bd456af3ec < e1ac8dce3a893641bef224ad057932f142b8a36fe1ac8dce3a893641bef224ad057932f142b8a36f
linuxlinux>= be102eb6a0e7c03db00e50540622f4e43b2d2844 < 2e2a720766886190a6d35c116794693aabd332b62e2a720766886190a6d35c116794693aabd332b6
linuxlinux>= da9f247fb5efcd5a2730cdc989291b383c439e10 < 325eb61bb30790ea27782203a17b007ce1754a67325eb61bb30790ea27782203a17b007ce1754a67
linuxlinux>= f6904ed15ed1a188543057e3cb0d02daa80edfc9 < 4bd2b89f4028f250dd1c1625eb3da1979b04a5e84bd2b89f4028f250dd1c1625eb3da1979b04a5e8
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 6.17.13 < 6.186.18
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-gcp
ubuntulinux-gcp-6.17
ubuntulinux-hwe-6.17

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.