Executive brief
The Linux kernel's netfilter subsystem contains a bug in the nft_payload module that handles network packet filtering rules. When processing partial IPv6 address matches, the code performs an undefined bitwise shift operation that triggers a crash. This can allow a local attacker or someone with access to netfilter configuration to cause a kernel panic, disrupting network services and availability.
Technical details
The vulnerability is a shift-out-of-bounds undefined behavior in the nft_payload_offload_mask() function in net/netfilter/nft_payload.c. The bug occurs when building an offload match mask for partial header field expressions—specifically when processing IPv6 addresses with field_len=16 and priv_len=1, which results in a shift of 1 << 120 on a 32-bit integer, exceeding the valid range. The vulnerable code also incorrectly masks trailing bytes, leaving the mask covering more data than intended. The attack vector requires local or configuration-level access to set up malicious netfilter rules. The fix simplifies the mask logic by directly setting the first priv_len bytes to 0xff, eliminating the undefined shift and correcting the byte-granular masking. Patches are available in the Linux kernel stable releases.
Affected products
- Linux Linux Kernel multiple versions through 2026 (netfilter nft_payload module)
Timeline
- 2026-08-17: disclosed: CVE-2026-74579 published
- 2026-08-09: patched: Patch committed to stable kernel branches
- 2026-07-19: other: Fix authored by Xiang Mei (Microsoft)