Junglewise Threat Intelligence

CVE-2026-43450: Linux Kernel Netfilter out-of-bounds read in nfnetlink_cthelper

CVE-2026-43450 · Severity: high · CVSS 7.1 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Netfilter component, which manages network traffic filtering and connection tracking. An attacker with local access could exploit a flaw in how the system lists connection tracking helpers to read sensitive information from the computer's memory that they should not be able to access. This could lead to the exposure of system data or cause the operating system to crash, impacting the stability and security of the server.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the nfnl_cthelper_dump_table() function within the netfilter/nfnetlink_cthelper.c component of the Linux kernel. The flaw is caused by a 'goto restart' statement positioned outside of a for-loop's bounds check. When a connection tracking helper is deleted between dump rounds, the loop index can reach the maximum hash size (nf_ct_helper_hsize); the subsequent 'goto' then bypasses the loop's entry condition, resulting in an 8-byte OOB read from the nf_ct_helper_hash array. This can be triggered by a local user via Netlink messages. Patches have been released across multiple stable kernel branches to move the restart logic inside the loop body.

Affected products

  • Linux Linux Kernel 3.6 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1 to 7.0-rc3

Timeline

  • 2026-03-19: patched: Patch committed to stable tree by Greg Kroah-Hartman
  • 2026-05-08: disclosed: CVE published by kernel.org

References

Related threats