Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-43114

 

Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-43114

Published: May 7, 2026


Vulnerability identifier: #VU130641
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-43114
CWE-ID: CWE-670
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of stale bits in nft_set_pipapo_avx2 match functions in the netfilter pipapo set implementation when processing crafted set elements during avx2-based matching. A local user can load and reload a crafted pipapo set to cause a denial of service.

The issue occurs with avx2 matching functions and can cause a non-matching expired entry to be treated as a match after a set flush and reload operation.


Affected software

Linux kernel
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kpatch-patch-5_14_0-284_172_1 (Red Hat package)
kpatch-patch-5_14_0-687_10_1 (Red Hat package)
kpatch-patch-6_12_0-211_16_1 (Red Hat package)
kpatch-patch-5_14_0-427_126_1 (Red Hat package)
kpatch-patch-5_14_0-570_116_1 (Red Hat package)
kpatch-patch-5_14_0-284_158_1 (Red Hat package)
kpatch-patch-5_14_0-427_113_1 (Red Hat package)
kpatch-patch-5_14_0-570_94_1 (Red Hat package)
kpatch-patch-5_14_0-284_148_1 (Red Hat package)
kpatch-patch-5_14_0-427_100_1 (Red Hat package)
kpatch-patch-5_14_0-570_66_1 (Red Hat package)
kpatch-patch-5_14_0-284_134_1 (Red Hat package)
kpatch-patch-5_14_0-570_39_1 (Red Hat package)
kpatch-patch-5_14_0-427_84_1 (Red Hat package)
kpatch-patch-5_14_0-284_117_1 (Red Hat package)
kpatch-patch-5_14_0-427_68_2 (Red Hat package)
kpatch-patch-5_14_0-570_17_1 (Red Hat package)
kernel (Red Hat package)
linux (Ubuntu package)
linux-xilinx-zynqmp (Ubuntu package)
linux-raspi (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
Red Hat OpenShift Container Platform

How to mitigate CVE-2026-43114

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
kpatch-patch-5_14_0-284_172_1 (Red Hat package) - update to 1-8.el9_2
kpatch-patch-5_14_0-687_10_1 (Red Hat package) - update to 1-8.el9_8
kpatch-patch-6_12_0-211_16_1 (Red Hat package) - update to 1-8.el10_2
kpatch-patch-5_14_0-427_126_1 (Red Hat package) - update to 1-9.el9_4
kpatch-patch-5_14_0-570_116_1 (Red Hat package) - update to 1-9.el9_6
kpatch-patch-5_14_0-284_158_1 (Red Hat package) - update to 1-11.el9_2
kpatch-patch-5_14_0-427_113_1 (Red Hat package) - update to 1-12.el9_4
kpatch-patch-5_14_0-570_94_1 (Red Hat package) - update to 1-12.el9_6
kpatch-patch-5_14_0-284_148_1 (Red Hat package) - update to 1-13.el9_2
kpatch-patch-5_14_0-427_100_1 (Red Hat package) - update to 1-14.el9_4
kpatch-patch-5_14_0-570_66_1 (Red Hat package) - update to 1-14.el9_6
kpatch-patch-5_14_0-284_134_1 (Red Hat package) - update to 1-15.el9_2
kpatch-patch-5_14_0-570_39_1 (Red Hat package) - update to 1-15.el9_6
kpatch-patch-5_14_0-427_84_1 (Red Hat package) - update to 1-16.el9_4
kpatch-patch-5_14_0-284_117_1 (Red Hat package) - update to 1-21.el9_2
kpatch-patch-5_14_0-427_68_2 (Red Hat package) - update to 1-21.el9_4
kpatch-patch-5_14_0-570_17_1 (Red Hat package) - update to 1-24.el9_6
Red Hat OpenShift Container Platform - addressed in versions 4.19.47, 4.20.38, 4.21.33, 4.22.13
kernel (Red Hat package) - addressed in versions 5.14.0-284.191.1.el9_2, 5.14.0-427.149.1.el9_4, 5.14.0-570.138.1.el9_6, 5.14.0-687.42.1.el9_8, 6.12.0-55.103.1.el10_0
linux (Ubuntu package) - addressed in versions 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-134.134, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61+fips1, 6.8.0-1058.61~22.04.1, 6.8.0-1060.61, 6.8.0-1060.63+fips1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69, 6.8.0-1063.69+fips1, 6.8.1-1055.56, 6.8.1-1055.56~22.04.1, 6.17.0-40.40
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-raspi (Ubuntu package) - addressed in versions 5.15.0.1105.103, 5.15.0-1105.108, 6.8.0-1060.64, 6.17.0-1021.21
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1, 6.8.0-134.134+fips1, 6.8.0-1062.69+fips1
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1029.30
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1045.48, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61.1, 6.8.0-1058.64, 6.8.0-1060.61~22.04.1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69~22.04.1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2049.50
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28

External References

Related Security Bulletins