Junglewise Threat Intelligence

CVE-2026-52942: Linux Kernel netfilter out-of-bounds read in nf_log

CVE-2026-52942 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem that could allow a local user to trigger an out-of-bounds memory read. This occurs when the system attempts to log network packets that are missing specific header information, potentially causing the system to read data beyond the intended memory buffer. While primarily impacting system stability, such flaws can sometimes be used to leak sensitive kernel information into system logs.

Technical details

An out-of-bounds read vulnerability exists in the netfilter nf_log component of the Linux kernel. The function dump_mac_header() in net/netfilter/nf_log_syslog.c fails to verify if a MAC header was actually set using skb_mac_header_was_set() before accessing it. When an unset MAC header (indicated by 0xffff) is processed, the kernel calculates an offset approximately 64 KiB past the buffer head, leading to a slab-out-of-bounds read. This path is reachable via the netdev logger when packets are sent through AF_PACKET with PACKET_QDISC_BYPASS, which skips the standard header initialization. The fix involves adding explicit checks for skb_mac_header_was_set() and using skb_mac_header_len() to ensure valid memory access.

Affected products

  • Linux Linux Kernel 7eb9282cd0ef to d704ee9c7bc68a161684c51a7ac05b446dcf38d4

Timeline

  • 2026-06-09: other: Vulnerability fixed in upstream commits
  • 2026-06-24: disclosed: CVE published

References

Related threats