Answer in brief
CVE-2023-53635 records a High severity (CVSS 8.2) vulnerability in netfilter: conntrack: fix wrong ct->timeout value. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a4b4766c3cebb4018167e06b863d8e95b7274757 <80c5ba0078e20d926d11d0778f9a43902664ebf0 || >=a4b4766c3cebb4018167e06b863d8e95b7274757 <ff5e4ac8dd7be7f1faba955c5779a68571eeb0f8 || >=a4b4766c3cebb4018167e06b863d8e95b7274757 <f612ae1ab4793701caf39386fb3b7f4b3ef44e48 || >=a4b4766c3cebb4018167e06b863d8e95b7274757 <73db1b8f2bb6725b7391e85aab41fdf592b3c0c1 | 80c5ba0078e20d926d11d0778f9a43902664ebf0, ff5e4ac8dd7be7f1faba955c5779a68571eeb0f8, f612ae1ab4793701caf39386fb3b7f4b3ef44e48, 73db1b8f2bb6725b7391e85aab41fdf592b3c0c1 |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Oct 7, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: fix wrong ct->timeout value (struct nf_conn)->timeout is an interval before the conntrack confirmed. After confirmed, it becomes a timestamp. It is observed that timeout of an unconfirmed conntrack: - Set by calling ctnetlink_change_timeout(). As a result, `nfct_time_stamp` was wrongly added to `ct->timeout` twice. - Get by calling ctnetlink_dump_timeout(). As a result, `nfct_time_stamp` was wrongly subtracted. Call Trace: <TASK> dump_stack_lvl ctnetlink_dump_timeout __ctnetlink_glue_build ctnetlink_glue_build __nfqnl_enqueue_packet nf_queue nf_hook_slow ip_mc_output ? __pfx_ip_finish_output ip_send_skb ? __pfx_dst_output udp_send_skb udp_sendmsg ? __pfx_ip_generic_getfrag sock_sendmsg Separate the 2 cases in: - Setting `ct->timeout` in __nf_ct_set_timeout(). - Getting `ct->timeout` in ctnetlink_dump_timeout(). Pablo appends: Update ctnetlink to set up the timeout _after_ the IPS_CONFIRMED flag is set on, otherwise conntrack creation via ctnetlink breaks. Note that the problem described in this patch occurs since the introduction of the nfnetlink_queue conntrack support, select a sufficiently old Fixes: tag for -stable kernel to pick up this fix.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2023-53635 records a High severity (CVSS 8.2) vulnerability in netfilter: conntrack: fix wrong ct->timeout value. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a4b4766c3cebb4018167e06b863d8e95b7274757 <80c5ba0078e20d926d11d0778f9a43902664ebf0 || >=a4b4766c3cebb4018167e06b863d8e95b7274757 <ff5e4ac8dd7be7f1faba955c5779a68571eeb0f8 || >=a4b4766c3cebb4018167e06b863d8e95b7274757 <f612ae1ab4793701caf39386fb3b7f4b3ef44e48 || >=a4b4766c3cebb4018167e06b863d8e95b7274757 <73db1b8f2bb6725b7391e85aab41fdf592b3c0c1 | 80c5ba0078e20d926d11d0778f9a43902664ebf0, ff5e4ac8dd7be7f1faba955c5779a68571eeb0f8, f612ae1ab4793701caf39386fb3b7f4b3ef44e48, 73db1b8f2bb6725b7391e85aab41fdf592b3c0c1 |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Oct 7, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: fix wrong ct->timeout value (struct nf_conn)->timeout is an interval before the conntrack confirmed. After confirmed, it becomes a timestamp. It is observed that timeout of an unconfirmed conntrack: - Set by calling ctnetlink_change_timeout(). As a result, `nfct_time_stamp` was wrongly added to `ct->timeout` twice. - Get by calling ctnetlink_dump_timeout(). As a result, `nfct_time_stamp` was wrongly subtracted. Call Trace: <TASK> dump_stack_lvl ctnetlink_dump_timeout __ctnetlink_glue_build ctnetlink_glue_build __nfqnl_enqueue_packet nf_queue nf_hook_slow ip_mc_output ? __pfx_ip_finish_output ip_send_skb ? __pfx_dst_output udp_send_skb udp_sendmsg ? __pfx_ip_generic_getfrag sock_sendmsg Separate the 2 cases in: - Setting `ct->timeout` in __nf_ct_set_timeout(). - Getting `ct->timeout` in ctnetlink_dump_timeout(). Pablo appends: Update ctnetlink to set up the timeout _after_ the IPS_CONFIRMED flag is set on, otherwise conntrack creation via ctnetlink breaks. Note that the problem described in this patch occurs since the introduction of the nfnetlink_queue conntrack support, select a sufficiently old Fixes: tag for -stable kernel to pick up this fix.
Quoted source text, attributed separately from HOL analysis.