CVE-2026-63913: Linux Netfilter Conntrack Flaw Allows NAT Entry Manipulation
August 7, 2026
CVE-2026-63913 is a high-severity vulnerability (CVSS 8.2) in Linux Netfilter conntrack. A crafted SYN followed by a reset packet with an invalid sequence number can prematurely force an active NAT entry into a closed state due to improper direction validation. Fixed stable releases include 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.93, 6.18.35, 7.0.12, and 7.1. The fix mitigates but does not fully address the broader NatJack attack class.