Scheduled maintenance: Some features related to account registration and licensing may be temporarily unavailable from Friday (May 8) at 1 PM to Sunday (May 10) at 5 PM (PST).
HomeDefectsLIN1023-22822
Fixed

LIN1023-22822 : Security Advisory - linux - CVE-2026-43060

Created: May 5, 2026    Updated: May 7, 2026
Resolved Date: May 6, 2026
Found In Version: 10.23.30.2
Fix Version: 10.23.30.21
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_ct: drop pending enqueued packets on removal  Packets sitting in nfqueue might hold a reference to:  - templates that specify the conntrack zone, because a percpu area is   used and module removal is possible. - conntrack timeout policies and helper, where object removal leave   a stale reference.  Since these objects can just go away, drop enqueued packets to avoid stale reference to them.  If there is a need for finer grain removal, this logic can be revisited to make selective packet drop upon dependencies.