5.5

CVE-2026-43085

netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator

When batching multiple NFLOG messages (inst->qlen > 1), __nfulnl_send()
appends an NLMSG_DONE terminator with sizeof(struct nfgenmsg) payload via
nlmsg_put(), but never initializes the nfgenmsg bytes. The nlmsg_put()
helper only zeroes alignment padding after the payload, not the payload
itself, so four bytes of stale kernel heap data are leaked to userspace
in the NLMSG_DONE message body.

Use nfnl_msg_put() to build the NLMSG_DONE terminator, which initializes
the nfgenmsg payload via nfnl_fill_hdr(), consistent with how
__build_packet_message() already constructs NFULNL_MSG_PACKET headers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.23.1 < 5.10.258
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.209
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.175
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.136
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.83
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.24
Linux ≫ Linux Kernel Version >= 6.19 < 6.19.14
Linux ≫ Linux Kernel Version 2.6.23 Update -
Linux ≫ Linux Kernel Version 7.0 Update rc1
Linux ≫ Linux Kernel Version 7.0 Update rc2
Linux ≫ Linux Kernel Version 7.0 Update rc3
Linux ≫ Linux Kernel Version 7.0 Update rc4
Linux ≫ Linux Kernel Version 7.0 Update rc5
Linux ≫ Linux Kernel Version 7.0 Update rc6
Linux ≫ Linux Kernel Version 7.0 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.023
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/368c22aea490f6f50df831b4f9e3623787686c5b
Patch
https://git.kernel.org/stable/c/d1399632ba255d2e02c757af5d9f5d9279ce168c
Patch
https://git.kernel.org/stable/c/d552bcfca323d175664d7444989b04f55666978a
Patch
https://git.kernel.org/stable/c/15d209bccf9273b4a8b4e579ba0e92d065b6ec8c
Patch
https://git.kernel.org/stable/c/1f3083aec8836213da441270cdb1ab612dd82cf4
Patch
https://git.kernel.org/stable/c/296f18e1c3a87c915a92ed27832d5040a22d1072
Patch
https://git.kernel.org/stable/c/57cc509d82b46150a11dcecc8b25eaa177eda34d
Patch
https://git.kernel.org/stable/c/9e2182865de781c41ab16b7985e9d26dcefea867
Patch
https://cert-portal.siemens.com/productcert/html/ssa-019113.html