7.3
HIGH CVSS 3.1
CVE-2026-72347
netfilter: xt_connmark: reject invalid shift parameters
Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_connmark: reject invalid shift parameters Revision 2 of the CONNMARK target accepts user-controlled shift parameters and applies them to 32-bit mark values in connmark_tg_shift(). A shift_bits value of 32 or more triggers an undefined-shift bug when the rule is evaluated. Invalid shift_dir values are also accepted and silently fall back to the left-shift path. Reject invalid revision-2 shift parameters in connmark_tg_check() so malformed rules fail at installation time, before they can reach the packet path.

INFO

Published Date :

Aug. 15, 2026, 6:22 a.m.

Last Modified :

Aug. 17, 2026, 6:18 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-72347 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
The Linux kernel netfilter module has a resolved vulnerability in xt_connmark.
  • Update the Linux kernel to the latest version.
  • Apply security patches for netfilter.
  • Reject invalid revision-2 shift parameters.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-72347 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-72347 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-72347 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-72347 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': 'd8ce63d928b457fba7ed1e302492dfd32293671c', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '9657bb11a6376ab0a79f05d433713d6944111e9d', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '8ace320ac4416f5e5fbcd065309fb2dfcce787b0', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': 'c3fa852d117b3fda72265e4230e3967db4a74fcf', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '4eef84b09a3836919360c4232b0f16651a155eec', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '230173cc6105bdfb2696d37e6e56687b003fbe63', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '1b47026fb4b35bac850ad6e8a4ad7fc018e09ebc', 'versionType': 'git'}], 'programFiles': ['net/netfilter/xt_connmark.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.17'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.17', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc3', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/netfilter/xt_connmark.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': 'd8ce63d928b457fba7ed1e302492dfd32293671c', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '9657bb11a6376ab0a79f05d433713d6944111e9d', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '8ace320ac4416f5e5fbcd065309fb2dfcce787b0', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': 'c3fa852d117b3fda72265e4230e3967db4a74fcf', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '4eef84b09a3836919360c4232b0f16651a155eec', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '230173cc6105bdfb2696d37e6e56687b003fbe63', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '1b47026fb4b35bac850ad6e8a4ad7fc018e09ebc', 'versionType': 'git'}], 'programFiles': ['net/netfilter/xt_connmark.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.17'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.17', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/netfilter/xt_connmark.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': 'd8ce63d928b457fba7ed1e302492dfd32293671c', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '9657bb11a6376ab0a79f05d433713d6944111e9d', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '8ace320ac4416f5e5fbcd065309fb2dfcce787b0', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': 'c3fa852d117b3fda72265e4230e3967db4a74fcf', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '4eef84b09a3836919360c4232b0f16651a155eec', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '230173cc6105bdfb2696d37e6e56687b003fbe63', 'versionType': 'git'}, {'status': 'affected', 'version': '472a73e00757b971d613d796374d2727b2e4954d', 'lessThan': '1b47026fb4b35bac850ad6e8a4ad7fc018e09ebc', 'versionType': 'git'}], 'programFiles': ['net/netfilter/xt_connmark.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.17'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.17', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc3', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/netfilter/xt_connmark.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_connmark: reject invalid shift parameters Revision 2 of the CONNMARK target accepts user-controlled shift parameters and applies them to 32-bit mark values in connmark_tg_shift(). A shift_bits value of 32 or more triggers an undefined-shift bug when the rule is evaluated. Invalid shift_dir values are also accepted and silently fall back to the left-shift path. Reject invalid revision-2 shift parameters in connmark_tg_check() so malformed rules fail at installation time, before they can reach the packet path.
    Added Reference https://git.kernel.org/stable/c/1b47026fb4b35bac850ad6e8a4ad7fc018e09ebc
    Added Reference https://git.kernel.org/stable/c/230173cc6105bdfb2696d37e6e56687b003fbe63
    Added Reference https://git.kernel.org/stable/c/4eef84b09a3836919360c4232b0f16651a155eec
    Added Reference https://git.kernel.org/stable/c/8ace320ac4416f5e5fbcd065309fb2dfcce787b0
    Added Reference https://git.kernel.org/stable/c/9657bb11a6376ab0a79f05d433713d6944111e9d
    Added Reference https://git.kernel.org/stable/c/c3fa852d117b3fda72265e4230e3967db4a74fcf
    Added Reference https://git.kernel.org/stable/c/d8ce63d928b457fba7ed1e302492dfd32293671c
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.