CVE-2026-72430: net/sched: act_ct: fix nf_connlabels leak on two error paths
In the Linux kernel, the following vulnerability has been resolved:
net/sched: actct: fix nfconnlabels leak on two error paths
tcfctfillparams() calls nfconnlabelsget() (setting putlabels) when TCACTLABELS is present, but two later error sites use a bare return instead of "goto err", skipping the err: nfconnlabelsput() cleanup. They also precede the "p->putlabels = putlabels" assignment, so the tcfctparamsfree() fallback does not release the count either. Each failed RTMNEWACTION on these paths leaks one nfconnlabels reference: net->ct.labelsused is incremented and never released. The action is reachable with CAPNETADMIN over the netns, i.e. from an unprivileged user namespace on default-userns kernels.
Impact: an unprivileged user with CAPNETADMIN over a network namespace (e.g. via user namespaces) leaks one nfconnlabels reference per failed RTMNEWACTION on the two error paths; net->ct.labelsused is never released.
The err: label is safe to reach from both sites: p->tmpl is still NULL there (kzalloc'd, not yet assigned) and nfctput(NULL) is a no-op, so no inline release is needed.