Out-of-bounds read in Linux kernel - CVE-2026-52999
Published: June 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause incorrect logging behavior.
The vulnerability exists due to an out-of-bounds read in nf_osf_match_one() in nfnetlink_osf when processing TCP option matching across multiple fingerprints. A remote attacker can send specially crafted network traffic to cause incorrect logging behavior.
The issue is triggered when NF_OSF_LOGLEVEL_ALL is configured and matching continues after an earlier fingerprint match.
How to mitigate CVE-2026-52999
Sources
- https://git.kernel.org/stable/c/0145548346c4a30981a870a8ca00eac46ba27e85
- https://git.kernel.org/stable/c/1c136f2c44a5913646bac85303612fd0825197a0
- https://git.kernel.org/stable/c/1e19a07291bb8682c14c39a64725a3ae54ab8ccc
- https://git.kernel.org/stable/c/21883587593d7c8bb519a79460a0b5bc5ffbdabd
- https://git.kernel.org/stable/c/32e50f92c7cf3f4eba29622179a5fcdc2aebab41
- https://git.kernel.org/stable/c/70a3f31d25cf2ec9d4ddfa408120171ead955623
- https://git.kernel.org/stable/c/edb78a142d2e5948e63647c0646aa7e7886935f0
- https://git.kernel.org/stable/c/f5ca450087c3baf3651055e7a6de92600f827af3