Answer in brief
CVE-2026-72256 records a Unknown severity vulnerability in netfilter: xt_cluster: reject template conntracks in hash match. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72256 records a Unknown severity vulnerability in netfilter: xt_cluster: reject template conntracks in hash match. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0269ea4937343536ec7e85649932bc8c9686ea78 <4558bd7b47c7be82dffd837f27be8ea3ecee557d || >=0269ea4937343536ec7e85649932bc8c9686ea78 <d5f9d050b0b267227c1f02f11021872c7768a9cc || >=0269ea4937343536ec7e85649932bc8c9686ea78 <4cb8b5f586e41c187942291cc0938006077fa79e || >=0269ea4937343536ec7e85649932bc8c9686ea78 <fac2fdac3baad9ffd12b3b0bba4374d4b3585d54 || >=0269ea4937343536ec7e85649932bc8c9686ea78 <13ea4f86cf738c74be2146886ac261988a631e62 || >=0269ea4937343536ec7e85649932bc8c9686ea78 <07f9ddbf5e799c24a3a52ec9bd7b729a6f6d69d5 || >=0269ea4937343536ec7e85649932bc8c9686ea78 <5b2d4f0010018a7aa3495aa1dbf1b7a34011e7aa || >=0269ea4937343536ec7e85649932bc8c9686ea78 <5feba91006ec92da57acc1cc2e34df623b98541e | 4558bd7b47c7be82dffd837f27be8ea3ecee557d, d5f9d050b0b267227c1f02f11021872c7768a9cc, 4cb8b5f586e41c187942291cc0938006077fa79e, fac2fdac3baad9ffd12b3b0bba4374d4b3585d54, 13ea4f86cf738c74be2146886ac261988a631e62, 07f9ddbf5e799c24a3a52ec9bd7b729a6f6d69d5, 5b2d4f0010018a7aa3495aa1dbf1b7a34011e7aa, 5feba91006ec92da57acc1cc2e34df623b98541e |
| Linux/Linuxgeneric | 2.6.30 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_cluster: reject template conntracks in hash match xt_cluster_mt() treats any non-NULL nf_ct_get() result as a fully initialized conntrack and passes it to xt_cluster_hash(). This causes a state confusion bug when the raw table CT target attaches a template conntrack to skb->_nfct before normal conntrack processing. Templates carry IPS_TEMPLATE status but do not have a valid tuple for hashing yet, so xt_cluster_hash() can hit its WARN_ON() path on the zeroed l3num field. Reject template conntracks before hashing them. This matches existing netfilter handling for template objects and avoids hashing incomplete conntrack state.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0269ea4937343536ec7e85649932bc8c9686ea78 <4558bd7b47c7be82dffd837f27be8ea3ecee557d || >=0269ea4937343536ec7e85649932bc8c9686ea78 <d5f9d050b0b267227c1f02f11021872c7768a9cc || >=0269ea4937343536ec7e85649932bc8c9686ea78 <4cb8b5f586e41c187942291cc0938006077fa79e || >=0269ea4937343536ec7e85649932bc8c9686ea78 <fac2fdac3baad9ffd12b3b0bba4374d4b3585d54 || >=0269ea4937343536ec7e85649932bc8c9686ea78 <13ea4f86cf738c74be2146886ac261988a631e62 || >=0269ea4937343536ec7e85649932bc8c9686ea78 <07f9ddbf5e799c24a3a52ec9bd7b729a6f6d69d5 || >=0269ea4937343536ec7e85649932bc8c9686ea78 <5b2d4f0010018a7aa3495aa1dbf1b7a34011e7aa || >=0269ea4937343536ec7e85649932bc8c9686ea78 <5feba91006ec92da57acc1cc2e34df623b98541e | 4558bd7b47c7be82dffd837f27be8ea3ecee557d, d5f9d050b0b267227c1f02f11021872c7768a9cc, 4cb8b5f586e41c187942291cc0938006077fa79e, fac2fdac3baad9ffd12b3b0bba4374d4b3585d54, 13ea4f86cf738c74be2146886ac261988a631e62, 07f9ddbf5e799c24a3a52ec9bd7b729a6f6d69d5, 5b2d4f0010018a7aa3495aa1dbf1b7a34011e7aa, 5feba91006ec92da57acc1cc2e34df623b98541e |
| Linux/Linuxgeneric | 2.6.30 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_cluster: reject template conntracks in hash match xt_cluster_mt() treats any non-NULL nf_ct_get() result as a fully initialized conntrack and passes it to xt_cluster_hash(). This causes a state confusion bug when the raw table CT target attaches a template conntrack to skb->_nfct before normal conntrack processing. Templates carry IPS_TEMPLATE status but do not have a valid tuple for hashing yet, so xt_cluster_hash() can hit its WARN_ON() path on the zeroed l3num field. Reject template conntracks before hashing them. This matches existing netfilter handling for template objects and avoids hashing incomplete conntrack state.
Quoted source text, attributed separately from HOL analysis.