CVE-2026-43116 is a lifetime-management flaw in the Linux kernel's Netfilter ctnetlink functionality. Holding a reference to a connection-tracking expectation does not preserve the lifetime of its master conntrack object, allowing exp->master to become invalid when the master is freed concurrently. Insufficient locking affects expectation lookup in the get and delete commands and access to the master object's event cache during IPEXP_NEW delivery. The flaw can result in use-after-free access and a kernel crash or undefined kernel behavior. The add-expectation command already holds a master reference through ctnetlink_create_expect(), and IPEXP_DESTROY delivery is already protected by the expectation spinlock.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel Netfilter ctnetlink vulnerability involving unsafe access to the master connection-tracking object. The advisory lists affected Rocky Linux 10.2 kernel packages and recommends security updates.
A Linux kernel netfilter/ctnetlink object-lifetime flaw allows unsafe access to a master connection-tracking object after it disappears. The fix expands spinlock protection around expectation lookups and event delivery. The advisory assigns CVSS v3 severity High (7.8), with local access, low privileges, and no user interaction required; potential impacts affect confidentiality, integrity, and availability.
A Linux kernel netfilter ctnetlink flaw allows unsafe access to a master connection-tracking object after it has been removed. The fix expands locking around expectation lookups and event delivery to prevent the object from disappearing during access. The reference assigns a CVSS v3 score of 7.8, indicating local exploitation requiring low privileges and potentially high confidentiality, integrity, and availability impact.
A Linux kernel Netfilter/ctnetlink flaw involving unsafe access to the master conntrack object. It affects packages installed on the Rocky Linux 8 host covered by CIQ advisory crlsa-2026_49213.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.