7.1

CVE-2026-74579

netfilter: nft_payload: fix mask build for partial field offload

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_payload: fix mask build for partial field offload

nft_payload_offload_mask() builds the offload match mask for a payload
expression that covers only part of a header field.  For a partial IPv6
address match (field_len = 16, priv_len = 1) that shift is 1 << 120, which
is undefined on the 32-bit int operand.  It also trims only one word, so
the remaining words stay 0xffffffff (and when priv_len is a multiple of 4
the trim is skipped entirely), leaving the mask covering more bytes than
the rule matches.

  UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20
  shift exponent 120 is too large for 32-bit type 'int'
  ...

The match is byte-granular and struct nft_data is zero-initialised, so the
correct mask is simply the first priv_len bytes set to 0xff. Set those
bytes directly and drop the word/shift trimming; this removes the undefined
shift and no longer over-masks the trailing bytes.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version a5d45bc0dc50f9dd83703510e9804d813a9cac32
Version < 3ee7b3f813b11f28cd6efdf7f24d64b5a7fd4dc7
Status affected
Version a5d45bc0dc50f9dd83703510e9804d813a9cac32
Version < 8720df4504e0ed1781a702f65251bd47b3534d5e
Status affected
Version a5d45bc0dc50f9dd83703510e9804d813a9cac32
Version < 363c3a84a946d53e5e121c9f47c7c2b7d228c46b
Status affected
Version a5d45bc0dc50f9dd83703510e9804d813a9cac32
Version < b19b5d2e042c294e2cc1c908dc598f9d64015396
Status affected
Version a5d45bc0dc50f9dd83703510e9804d813a9cac32
Version < a375d8ace807767f29f276b681b6324c74929b1d
Status affected
Version a5d45bc0dc50f9dd83703510e9804d813a9cac32
Version < 16b553c46e347bc9de9946c4960654d5884a86de
Status affected
Version a5d45bc0dc50f9dd83703510e9804d813a9cac32
Version < 630295d5bba1d0e0f494cc459452eb0a0058c545
Status affected
Version a5d45bc0dc50f9dd83703510e9804d813a9cac32
Version < 39e88f28fb32bf02bd4b525c24c842c9cff5663d
Status affected
Version 5c2b4b4f9fa5b765b927e361e3d310bcb5773015
Status affected
Version 5.9.14
Version < 5.10
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.062
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b19b5d2e042c294e2cc1c908dc598f9d64015396
https://git.kernel.org/stable/c/a375d8ace807767f29f276b681b6324c74929b1d
https://git.kernel.org/stable/c/16b553c46e347bc9de9946c4960654d5884a86de
https://git.kernel.org/stable/c/630295d5bba1d0e0f494cc459452eb0a0058c545
https://git.kernel.org/stable/c/39e88f28fb32bf02bd4b525c24c842c9cff5663d
https://git.kernel.org/stable/c/363c3a84a946d53e5e121c9f47c7c2b7d228c46b
https://git.kernel.org/stable/c/3ee7b3f813b11f28cd6efdf7f24d64b5a7fd4dc7
https://git.kernel.org/stable/c/8720df4504e0ed1781a702f65251bd47b3534d5e