Linux Netfilter conntrack is affected by CVE-2026-63913, a high-severity vulnerability that allows an attacker to prematurely force NAT entries into a closed state. The flaw is due to improper direction validation in conntrack logic. Patches are available in multiple stable kernel releases.