nfqueue conntrack

  1. CVE-2026-23391 Fix: Flush nfqueue Packets When xt_CT Template Rules Are Removed

    Linux kernel maintainers have assigned CVE-2026-23391 to a netfilter / xt_CT race condition fix that drops packets still sitting in nfqueue when a template rule is removed. The issue matters because the template can reference stateful objects such as a helper module or a timeout policy, and...