Out-of-bounds write in Linux kernel - CVE-2026-72252
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to out-of-bounds writes in the nft_pipapo_match handling in netfilter nft_set_pipapo when processing set element insertions after a prior memory allocation failure left a cloned match in an invalid state. A local user can trigger an allocation failure and then perform a subsequent insertion in the same batch to cause memory corruption.
The issue can also affect a subsequent transaction because a bad clone may persist when the abort callback is not executed after the initial failure.
Affected software
How to mitigate CVE-2026-72252
External References
- https://git.kernel.org/stable/c/02b6b0e892aea582590671796fd6eff5b93ea93f
- https://git.kernel.org/stable/c/047e813324eac2ac60cddfb58bcdbd0144eadb09
- https://git.kernel.org/stable/c/47e65eff50691f0a5b79d325e28d83ec1da43bcf
- https://git.kernel.org/stable/c/610e3b73efaec3dd81a95dcda2421ad7d9795bd0
- https://git.kernel.org/stable/c/e74f9680e1b64872a51cc7b5bda1edaaa08aa51f