Executive brief
A vulnerability exists in the Linux kernel's Netfilter component, which is responsible for network traffic filtering and firewalling. A flaw in how the system handles complex network rule sets could allow a local user to trigger an out-of-bounds memory read. This could lead to a system crash (denial of service) or potentially expose sensitive information from the system's memory.
Technical details
An out-of-bounds read vulnerability exists in the pipapo_drop() function within net/netfilter/nft_set_pipapo.c in the Linux kernel. The issue stems from the function passing rulemap[i + 1].n to pipapo_unmap() during the final iteration of a loop, where 'i' equals the maximum field count minus one. This causes the kernel to read 4 bytes beyond the end of the stack-allocated 'rulemap' array. While the called function (pipapo_unmap) may not use the value if a 'last' flag is set, the argument evaluation at the call site triggers the out-of-bounds access. This was confirmed via KASAN (Kernel Address Sanitizer). A local attacker with low privileges can exploit this to cause a kernel panic or leak stack memory. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.6 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1 to 7.0-rc3
Timeline
- 2026-03-06: other: Vulnerability fixed in source code
- 2026-05-08: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0a55d62cdb628923d8a21724374a70c76ac7d19d
- https://git.kernel.org/stable/c/1957e793196e7f8557374fd4eda53abcbb42e1c0
- https://git.kernel.org/stable/c/324b749aa5b2d516ccfab933df9d3f56e7807f5f
- https://git.kernel.org/stable/c/57fb87ca095d5127cd7a27583b8ec43dcf7c9e9e
- https://git.kernel.org/stable/c/60c1d18781e37bfb96290b86510eb01c5fa24d75
- https://git.kernel.org/stable/c/d6d8cd2db236a9dd13dbc2d05843b3445cc964b5
- https://git.kernel.org/stable/c/dfbdac719198778b581bc0dd055df2542edb8c62