Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-43114
Published: May 7, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of stale bits in nft_set_pipapo_avx2 match functions in the netfilter pipapo set implementation when processing crafted set elements during avx2-based matching. A local user can load and reload a crafted pipapo set to cause a denial of service.
The issue occurs with avx2 matching functions and can cause a non-matching expired entry to be treated as a match after a set flush and reload operation.
Affected software
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kpatch-patch-5_14_0-284_172_1 (Red Hat package)
kpatch-patch-5_14_0-687_10_1 (Red Hat package)
kpatch-patch-6_12_0-211_16_1 (Red Hat package)
kpatch-patch-5_14_0-427_126_1 (Red Hat package)
kpatch-patch-5_14_0-570_116_1 (Red Hat package)
kpatch-patch-5_14_0-284_158_1 (Red Hat package)
kpatch-patch-5_14_0-427_113_1 (Red Hat package)
kpatch-patch-5_14_0-570_94_1 (Red Hat package)
kpatch-patch-5_14_0-284_148_1 (Red Hat package)
kpatch-patch-5_14_0-427_100_1 (Red Hat package)
kpatch-patch-5_14_0-570_66_1 (Red Hat package)
kpatch-patch-5_14_0-284_134_1 (Red Hat package)
kpatch-patch-5_14_0-570_39_1 (Red Hat package)
kpatch-patch-5_14_0-427_84_1 (Red Hat package)
kpatch-patch-5_14_0-284_117_1 (Red Hat package)
kpatch-patch-5_14_0-427_68_2 (Red Hat package)
kpatch-patch-5_14_0-570_17_1 (Red Hat package)
kernel (Red Hat package)
linux (Ubuntu package)
linux-xilinx-zynqmp (Ubuntu package)
linux-raspi (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2026-43114
kpatch-patch-5_14_0-284_172_1 (Red Hat package) - update to 1-8.el9_2
kpatch-patch-5_14_0-687_10_1 (Red Hat package) - update to 1-8.el9_8
kpatch-patch-6_12_0-211_16_1 (Red Hat package) - update to 1-8.el10_2
kpatch-patch-5_14_0-427_126_1 (Red Hat package) - update to 1-9.el9_4
kpatch-patch-5_14_0-570_116_1 (Red Hat package) - update to 1-9.el9_6
kpatch-patch-5_14_0-284_158_1 (Red Hat package) - update to 1-11.el9_2
kpatch-patch-5_14_0-427_113_1 (Red Hat package) - update to 1-12.el9_4
kpatch-patch-5_14_0-570_94_1 (Red Hat package) - update to 1-12.el9_6
kpatch-patch-5_14_0-284_148_1 (Red Hat package) - update to 1-13.el9_2
kpatch-patch-5_14_0-427_100_1 (Red Hat package) - update to 1-14.el9_4
kpatch-patch-5_14_0-570_66_1 (Red Hat package) - update to 1-14.el9_6
kpatch-patch-5_14_0-284_134_1 (Red Hat package) - update to 1-15.el9_2
kpatch-patch-5_14_0-570_39_1 (Red Hat package) - update to 1-15.el9_6
kpatch-patch-5_14_0-427_84_1 (Red Hat package) - update to 1-16.el9_4
kpatch-patch-5_14_0-284_117_1 (Red Hat package) - update to 1-21.el9_2
kpatch-patch-5_14_0-427_68_2 (Red Hat package) - update to 1-21.el9_4
kpatch-patch-5_14_0-570_17_1 (Red Hat package) - update to 1-24.el9_6
Red Hat OpenShift Container Platform - addressed in versions 4.19.47, 4.20.38, 4.21.33, 4.22.13
kernel (Red Hat package) - addressed in versions 5.14.0-284.191.1.el9_2, 5.14.0-427.149.1.el9_4, 5.14.0-570.138.1.el9_6, 5.14.0-687.42.1.el9_8, 6.12.0-55.103.1.el10_0
linux (Ubuntu package) - addressed in versions 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-134.134, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61+fips1, 6.8.0-1058.61~22.04.1, 6.8.0-1060.61, 6.8.0-1060.63+fips1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69, 6.8.0-1063.69+fips1, 6.8.1-1055.56, 6.8.1-1055.56~22.04.1, 6.17.0-40.40
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-raspi (Ubuntu package) - addressed in versions 5.15.0.1105.103, 5.15.0-1105.108, 6.8.0-1060.64, 6.17.0-1021.21
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1, 6.8.0-134.134+fips1, 6.8.0-1062.69+fips1
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1029.30
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1045.48, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61.1, 6.8.0-1058.64, 6.8.0-1060.61~22.04.1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69~22.04.1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2049.50
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28
External References
- https://git.kernel.org/stable/c/07de44424bb7f17ef9357e8535df96d9e97c40cb
- https://git.kernel.org/stable/c/0abbc43f71d99baadeeba6fa3fe1c80b676f57ed
- https://git.kernel.org/stable/c/3d53f9aafd469ae1ea27051e00f5b96ca1b55d52
- https://git.kernel.org/stable/c/d3c0037ffe1273fa1961e779ff6906234d6cf53c
- https://git.kernel.org/stable/c/fa4f1f52528c73989d820f32bfca06bec5afeece
Related Security Bulletins
- Always-Incorrect Control Flow Implementation in Linux kernel netfilter
- Ubuntu update for linux-oem-6.17
- Ubuntu update for linux
- Ubuntu update for linux
- Ubuntu update for linux
- Ubuntu update for linux-nvidia-tegra
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-oracle-5.15
- Ubuntu update for linux-nvidia-6.17
- Ubuntu update for linux-raspi-realtime
- Ubuntu update for linux-raspi
- Ubuntu update for linux-raspi
- Ubuntu update for linux-xilinx-zynqmp
- Ubuntu update for linux-raspi
- Ubuntu update for linux-azure-fips
- Ubuntu update for linux-hwe-6.17
- Ubuntu update for linux-raspi
- Ubuntu update for linux-gcp-5.15
- Ubuntu update for linux-azure-fde-6.8
- Ubuntu update for linux-azure-fde
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-fde-6.17
- Ubuntu update for linux-azure-6.17
- Ubuntu update for linux-azure-fips
- Ubuntu update for linux-hwe-6.8
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 9 update for kpatch-patch-5_14_0-687_10_1
- Red Hat Enterprise Linux 9 update for multiple packages
- Red Hat Enterprise Linux 10 update for kpatch-patch-6_12_0-211_16_1
- Red Hat Enterprise Linux 10 update for kernel
- Always-Incorrect Control Flow Implementation in Red Hat OpenShift Container Platform 4.22
- Red Hat Enterprise Linux 9 update for kernel
- Always-Incorrect Control Flow Implementation in Red Hat OpenShift Container Platform 4.21
- Always-Incorrect Control Flow Implementation in Red Hat OpenShift Container Platform 4.20
- Red Hat Enterprise Linux 9 update for kernel
- Always-Incorrect Control Flow Implementation in Red Hat OpenShift Container Platform 4.19