In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without… (CVE-2026-63913)
A vulnerability in the Linux kernel's netfilter conntrack TCP state machine allows a connection to be prematurely closed by sending a crafted RST packet with an invalid sequence number. This occurs because the state machine does not verify the direction of the RST packet or confirm that a matching SYN was sent in the opposite direction before forcing the connection state to CLOSE. The issue has been resolved by tightening the state transition logic to ensure RST-triggered CLOSE transitions only happen when the RST is a valid response to a previously observed SYN in the correct direction.
AI Analysis
Technical Summary
The Linux kernel netfilter conntrack TCP implementation contained a flaw where an RST packet with an invalid sequence number could force a connection into the CLOSE state without verifying the packet's direction or the existence of a corresponding SYN in the opposite direction. This unintended behavior allowed a crafted sequence of a SYN followed by an invalid-sequence RST to prematurely terminate an active NAT connection entry. The fix involves strengthening the state transition logic to validate that RST-triggered CLOSE transitions only occur when the RST is a valid response to a previously observed SYN in the correct direction.
Potential Impact
An attacker capable of sending crafted TCP packets can prematurely terminate active NAT connection tracking entries by exploiting this flaw. This could disrupt legitimate network connections by forcing their teardown earlier than intended. There is no indication of remote code execution or privilege escalation. The impact is limited to connection teardown behavior within the netfilter conntrack subsystem.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by tightening the TCP conntrack state machine logic. Users should apply the official Linux kernel updates that address this issue. Since no vendor advisory or patch links are provided here, users should consult their Linux distribution's security advisories for the relevant kernel updates. Patch status is not yet confirmed in this data; verify with vendor advisories for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without… (CVE-2026-63913)
Description
A vulnerability in the Linux kernel's netfilter conntrack TCP state machine allows a connection to be prematurely closed by sending a crafted RST packet with an invalid sequence number. This occurs because the state machine does not verify the direction of the RST packet or confirm that a matching SYN was sent in the opposite direction before forcing the connection state to CLOSE. The issue has been resolved by tightening the state transition logic to ensure RST-triggered CLOSE transitions only happen when the RST is a valid response to a previously observed SYN in the correct direction.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel netfilter conntrack TCP implementation contained a flaw where an RST packet with an invalid sequence number could force a connection into the CLOSE state without verifying the packet's direction or the existence of a corresponding SYN in the opposite direction. This unintended behavior allowed a crafted sequence of a SYN followed by an invalid-sequence RST to prematurely terminate an active NAT connection entry. The fix involves strengthening the state transition logic to validate that RST-triggered CLOSE transitions only occur when the RST is a valid response to a previously observed SYN in the correct direction.
Potential Impact
An attacker capable of sending crafted TCP packets can prematurely terminate active NAT connection tracking entries by exploiting this flaw. This could disrupt legitimate network connections by forcing their teardown earlier than intended. There is no indication of remote code execution or privilege escalation. The impact is limited to connection teardown behavior within the netfilter conntrack subsystem.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by tightening the TCP conntrack state machine logic. Users should apply the official Linux kernel updates that address this issue. Since no vendor advisory or patch links are provided here, users should consult their Linux distribution's security advisories for the relevant kernel updates. Patch status is not yet confirmed in this data; verify with vendor advisories for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8577-pmm3-chq2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63913"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27ab2a4a8d598912f906
Added to database: 07/19/2026, 19:38:19 UTC
Last enriched: 07/19/2026, 20:09:39 UTC
Last updated: 07/20/2026, 17:26:47 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.