CVE-2026-43452 PUBLISHED

netfilter: x_tables: guard option walkers against 1-byte tail reads

Assigner: Linux
Reserved: 01.05.2026 Published: 08.05.2026 Updated: 08.05.2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: x_tables: guard option walkers against 1-byte tail reads

When the last byte of options is a non-single-byte option kind, walkers that advance with i += op[i + 1] ? : 1 can read op[i + 1] past the end of the option area.

Add an explicit i == optlen - 1 check before dereferencing op[i + 1] in xt_tcpudp and xt_dccp option walkers.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 2e4e6a17af35be359cc8f1c924f8f198fbd478cc to c2a445367a496a3c25dbc940c10c8bd1cfd4c14a (excl.)
  • affected from 2e4e6a17af35be359cc8f1c924f8f198fbd478cc to ae1e1267650638136b84c23f2b31250f0ccb6823 (excl.)
  • affected from 2e4e6a17af35be359cc8f1c924f8f198fbd478cc to c39f84e4be1be63fc60ca7141ea7b76edcea5907 (excl.)
  • affected from 2e4e6a17af35be359cc8f1c924f8f198fbd478cc to 9b94f0e42ed248eb31929da84ed9f5310d7ff540 (excl.)
  • affected from 2e4e6a17af35be359cc8f1c924f8f198fbd478cc to 5b18b8b35c7cded2d17b2b2604c9b0694ff48d1c (excl.)
  • affected from 2e4e6a17af35be359cc8f1c924f8f198fbd478cc to bc18551c6169eac5ed813778d3e3e484002dbbe5 (excl.)
  • affected from 2e4e6a17af35be359cc8f1c924f8f198fbd478cc to d04800323336eebf441d153f43234eac9b833d36 (excl.)
  • affected from 2e4e6a17af35be359cc8f1c924f8f198fbd478cc to cfe770220ac2dbd3e104c6b45094037455da81d4 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.16 is affected
  • unaffected from 0 to 2.6.16 (excl.)
  • unaffected from 5.10.253 to 5.10.* (incl.)
  • unaffected from 5.15.203 to 5.15.* (incl.)
  • unaffected from 6.1.167 to 6.1.* (incl.)
  • unaffected from 6.6.130 to 6.6.* (incl.)
  • unaffected from 6.12.78 to 6.12.* (incl.)
  • unaffected from 6.18.19 to 6.18.* (incl.)
  • unaffected from 6.19.9 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References