Junglewise Threat Intelligence

CVE-2026-74579: Linux kernel netfilter nft_payload shift-out-of-bounds

CVE-2026-74579 · Severity: high · CVSS 7.1 · Published 2026-08-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's netfilter subsystem contains a bug in the nft_payload module that handles network packet filtering rules. When processing partial IPv6 address matches, the code performs an undefined bitwise shift operation that triggers a crash. This can allow a local attacker or someone with access to netfilter configuration to cause a kernel panic, disrupting network services and availability.

Technical details

The vulnerability is a shift-out-of-bounds undefined behavior in the nft_payload_offload_mask() function in net/netfilter/nft_payload.c. The bug occurs when building an offload match mask for partial header field expressions—specifically when processing IPv6 addresses with field_len=16 and priv_len=1, which results in a shift of 1 << 120 on a 32-bit integer, exceeding the valid range. The vulnerable code also incorrectly masks trailing bytes, leaving the mask covering more data than intended. The attack vector requires local or configuration-level access to set up malicious netfilter rules. The fix simplifies the mask logic by directly setting the first priv_len bytes to 0xff, eliminating the undefined shift and correcting the byte-granular masking. Patches are available in the Linux kernel stable releases.

Affected products

  • Linux Linux Kernel multiple versions through 2026 (netfilter nft_payload module)

Timeline

  • 2026-08-17: disclosed: CVE-2026-74579 published
  • 2026-08-09: patched: Patch committed to stable kernel branches
  • 2026-07-19: other: Fix authored by Xiang Mei (Microsoft)

References

Related threats