SB2026050883 - Out-of-bounds read in Linux kernel netfilter
Published: May 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-43452)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the xt_tcpudp and xt_dccp option walkers when parsing malformed TCP or DCCP options. A remote attacker can send a specially crafted packet to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5b18b8b35c7cded2d17b2b2604c9b0694ff48d1c
- https://git.kernel.org/stable/c/9b94f0e42ed248eb31929da84ed9f5310d7ff540
- https://git.kernel.org/stable/c/ae1e1267650638136b84c23f2b31250f0ccb6823
- https://git.kernel.org/stable/c/bc18551c6169eac5ed813778d3e3e484002dbbe5
- https://git.kernel.org/stable/c/c2a445367a496a3c25dbc940c10c8bd1cfd4c14a
- https://git.kernel.org/stable/c/c39f84e4be1be63fc60ca7141ea7b76edcea5907
- https://git.kernel.org/stable/c/cfe770220ac2dbd3e104c6b45094037455da81d4
- https://git.kernel.org/stable/c/d04800323336eebf441d153f43234eac9b833d36