CVE-2026-23016Improper Update of Reference Count in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 94.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31

Description

In the Linux kernel, the following vulnerability has been resolved: inet: frags: drop fraglist conntrack references Jakub added a warning in nf_conntrack_cleanup_net_list() to make debugging leaked skbs/conntrack references more obvious. syzbot reports this as triggering, and I can also reproduce this via ip_defrag.sh selftest: conntrack cleanup blocked for 60s WARNING: net/netfilter/nf_conntrack_core.c:2512 [..] conntrack clenups gets stuck because there are skbs with still hold nf_conn re

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Linuxlinux/linux_kernel6.18.06.18.6
NVDlinux/linux_kernel6.18.16.18.6+2
Debianlinux/linux_kernel< 6.18.8-1
CVEListV5linux/linux6471658dc66c670580a7616e75f51b52917e7883088ca99dbb039c444c3ff987c5412a73f4f0cbf8+2
debiandebian/linux< linux 6.18.8-1 (forky)

Patches

🔴Vulnerability Details

3
OSV
CVE-2026-23016: In the Linux kernel, the following vulnerability has been resolved: inet: frags: drop fraglist conntrack references Jakub added a warning in nf_conntr2026-01-31
OSV
inet: frags: drop fraglist conntrack references2026-01-31
GHSA
GHSA-8h8q-4wvg-mhgm: In the Linux kernel, the following vulnerability has been resolved: inet: frags: drop fraglist conntrack references Jakub added a warning in nf_conn2026-01-31

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Denial of Service due to improper network connection tracking reference handling2026-01-31
Debian
CVE-2026-23016: linux - In the Linux kernel, the following vulnerability has been resolved: inet: frags...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23016 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23016 — Improper Update of Reference Count | cvebase