In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_ct: drop pending enqueued packets on removal
Packets sitting in nfqueue might hold a reference to:
Since these objects can just go away, drop enqueued packets to avoid stale reference to them.
If there is a need for finer grain removal, this logic can be revisited to make selective packet drop upon dependencies.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43060.json",
"cna_assigner": "Linux"
}