SB20260816129 - Out-of-bounds write in Linux kernel netfilter
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-72252)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to out-of-bounds writes in the nft_pipapo_match handling in netfilter nft_set_pipapo when processing set element insertions after a prior memory allocation failure left a cloned match in an invalid state. A local user can trigger an allocation failure and then perform a subsequent insertion in the same batch to cause memory corruption.
The issue can also affect a subsequent transaction because a bad clone may persist when the abort callback is not executed after the initial failure.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/02b6b0e892aea582590671796fd6eff5b93ea93f
- https://git.kernel.org/stable/c/047e813324eac2ac60cddfb58bcdbd0144eadb09
- https://git.kernel.org/stable/c/47e65eff50691f0a5b79d325e28d83ec1da43bcf
- https://git.kernel.org/stable/c/610e3b73efaec3dd81a95dcda2421ad7d9795bd0
- https://git.kernel.org/stable/c/e74f9680e1b64872a51cc7b5bda1edaaa08aa51f