Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72256

Published Aug 15, 2026 EPSS 0.22% (12th pctl)

Overview

CVE-2026-72256 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_cluster: reject template conntracks in hash match

xt_cluster_mt() treats any non-NULL nf_ct_get() result as a fully

initialized conntrack and passes it to xt_cluster_hash().

This causes a state confusion bug when the raw table CT target attaches

a template conntrack to skb->_nfct before normal conntrack processing.

Templates carry IPS_TEMPLATE status but do not have a valid tuple for

hashing yet, so xt_cluster_hash() can hit its WARN_ON() path on the

zeroed l3num field.

Reject template conntracks before hashing them. This matches existing

netfilter handling for template objects and avoids hashing incomplete

conntrack state.

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72256?

CVE-2026-72256 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-72256?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-72256?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72256?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72256 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.