Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — netfilter: allow exp not to be removed in nf_ct_find_expectation
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0027 19.0 —
AFFECTED
Product Versions Fixed
Linux 1bc91a5ddf3eaea0e0ea957cccf3abdcfcace00e – —
Linux 5.18 – 6.1.130
TIMELINE
Aug 21 Reserved by Linux
Mar 14 Published (CNA: Linux)
Aug 4 EXPLOIT PUBLISHED — CVE-2023-52927 (Linux). Public exploit reference added.
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: allow exp not to be removed in nf_ct_find_expectation
Currently nf_conntrack_in() calling nf_ct_find_expectation() will
remove the exp from the hash table. However, in some scenario, we
expect the exp not to be removed when the created ct will not be
confirmed, like in OVS and TC conntrack in the following patches.
This patch allows exp not to be removed by setting IPS_CONFIRMED
in the status of the tmpl.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 21, 2024 | Reserved | Reserved by Linux |
| March 14, 2025 | Published | Published (CNA: Linux) |
| August 4, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2023-52927 (Linux). Public exploit reference added. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 1bc91a5ddf3eaea0e0ea957cccf3abdcfcace00e | — |
| Linux | Linux | — | 5.18 | 6.1.130 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-52927 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.