Sceawere
Vulnerability Detail
CVE-2026-98251UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Open vSwitch Conntrack Extension Race
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: openvswitch: avoid reallocating confirmed conntrack labels ovs_ct_get_conn_labels() adds the labels extension when a conntrack entry does not have one. Confirmed conntracks can be read locklessly, so adding an extension may reallocate and free the extension block while another CPU accesses it. Only add the extension for unconfirmed conntracks. A confirmed conntrack without labels now fails the caller's label operation instead of reallocating its extension storage.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-06T09:18:13.567Z",
"pubdate": "2026-10-06T09:18:13.567Z",
"executiveSummary": "This vulnerability involves a race condition in the Linux kernel's Open vSwitch (OVS) module during the handling of conntrack labels. The issue stems from an unsafe attempt to dynamically reallocate and extend conntrack labels on confirmed entries, which are subject to lockless read operations.\nThe vulnerability type is a Race Condition leading to potential Use-After-Free (UAF) or memory corruption scenarios. The primary impact involves system instability, such as kernel panics or potential arbitrary code execution, depending on the memory layout and heap state.\nAffected systems are those running the Linux kernel with the Open vSwitch module enabled. The risk is significant for high-traffic environments where conntrack entries are frequently processed across multiple CPU cores.\nExploitation requires the ability to trigger conntrack label operations on established (confirmed) connections while concurrent threads are performing lockless reads of the same connection tracking state. This effectively makes it a localized memory management flaw triggered by concurrent networking operations.",
"technicalDetails": "The root cause of the vulnerability lies within the function ovs_ct_get_conn_labels() in the Open vSwitch module. In the Linux kernel, conntrack entries that have transitioned to the 'confirmed' state are permitted to be read locklessly for performance reasons. However, the existing implementation of ovs_ct_get_conn_labels() attempted to append a labels extension to these confirmed entries if they did not already possess one.\nThe process of adding an extension involves memory reallocation. When the kernel determines that a labels extension is missing, it initiates an extension allocation. If the conntrack entry is already confirmed, this reallocation process may free the existing extension block while other CPU cores are concurrently traversing the conntrack state or reading the labels extension.\nThe attack flow occurs when an attacker triggers a network operation that necessitates OVS conntrack label manipulation on an entry that is currently being accessed by another thread. Because confirmed conntrack entries provide no synchronization for these label extensions, the reallocation creates a window of time where a pointer to the previous memory location becomes dangling. Any subsequent lockless read attempt by a separate process results in accessing deallocated memory (Use-After-Free).\nThis behavior exposes the kernel heap to corruption. Depending on the timing and the state of the slab allocator, an attacker might influence the content of the memory by triggering specific object allocations that reclaim the freed memory block. This could potentially lead to controlled kernel memory corruption or a crash due to page faulting in an invalid memory region.\nThe vulnerability is inherent to the logic of the extension management within the OVS conntrack infrastructure. By restricting the extension addition process exclusively to unconfirmed conntrack entries, the kernel avoids the need to resize structures that are currently 'in-flight' and visible to the lockless read path. The fix ensures that any attempt to perform label operations on a confirmed conntrack entry without an existing labels extension will fail gracefully rather than invoking an unsafe memory reallocation.\nThis flaw does not require special authentication, but it does require the ability to send network traffic that is processed through the OVS module, necessitating a configuration that utilizes conntrack features."
}