← Volver al buscador de CVEs

CVE-2026-43114

Linux Kernel

Descripción

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don-t return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with -ipv4 . port- key, i.e. nft -f foo. This works. Then, it reloads the set after a flush: (echo flush set t s; cat foo) | nft -f - This is expected to work, because its the same set after all and it was already loaded once. But with avx2, this fails: nft reports a clashing element. The reported clash is of following form: We successfully re-inserted a . b c . d Then we try to insert a . d avx2 finds the already existing a . d, which (due to -flush set-) is marked as invalid in the new generation. It skips the element and moves to next. Due to incorrect masking, the skip-step finds the next matching element *only considering the first field*, i.e. we return the already reinserted -a . b-, even though the last field is diff...

CVSS 9.4EPSS 0.356%Riesgo 0.97
Ver fuente
Publicación
2026-05-06 10:16:25
Versiones afectadas
unknown
Tipo
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Sistemas operativos
Linux