Junglewise Threat Intelligence

CVE-2026-43452: Linux Kernel out-of-bounds read in Netfilter x_tables

CVE-2026-43452 · Severity: high · CVSS 8.2 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow an attacker to cause a system crash or potentially access sensitive information from the computer's memory. This issue affects the Netfilter component, which is responsible for firewalling and network traffic filtering. By sending specially crafted network packets, an attacker could disrupt services or gain unauthorized insights into system operations.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's Netfilter x_tables component, specifically within the xt_tcpudp and xt_dccp option walkers. When processing network packets where the last byte of the options field is a non-single-byte option kind, the walker incorrectly attempts to read the next byte (the length field) which resides past the end of the allocated option area. This occurs because the loop logic `i += op[i + 1] ? : 1` lacks a boundary check for the final byte. An attacker can trigger this by sending malformed TCP, UDP, or DCCP packets. The fix introduces an explicit check `i == optlen - 1` to prevent dereferencing memory beyond the option buffer. Patches have been backported to multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 2.6.16 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9

Timeline

  • 2026-03-07: other: Vulnerability fix authored
  • 2026-05-08: advisory: Initial disclosure and publication
  • 2026-05-21: other: NVD analysis and CPE mapping updated

References

Related threats