CVE-2026-80636

Source
https://cve.org/CVERecord?id=CVE-2026-80636
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80636.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80636
Downstream
Published
2026-08-28T06:48:50.241Z
Modified
2026-08-29T03:47:16.950398258Z
Summary
netfilter: conntrack: revert ct extension genid infrastructure
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: conntrack: revert ct extension genid infrastructure

This infrastructure is not used anymore after moving ct timeout and helper to use datapath refcount to track object use.

Revert commit c56716c69ce1 ("netfilter: extensions: introduce extension genid count") this patch disables all ct extensions (leading to NULL) for unconfirmed conntracks, when this is only targeted at ct helper and ct timeout. There is also codebase that dereferences the ct extension without checking for NULL which could lead to crash.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80636.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c56716c69ce1ac320432fb1ea5654196ba24d2f8
Fixed
6bba4846f196d081bf553391d12b5a73dcc48685
Fixed
61eab1d0237eb513fe73e391a5926ee70092c325
Fixed
d53eecbca16f056abba274075cb15120ab062518
Fixed
a052a94bcc629acaecc2ce42a4af77f8fa399757
Fixed
35e21a4dccc5c255ba59ccfbfeb4629ed21da972

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80636.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80636.json"