CVE-2026-43453 Details
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() pipapo_drop() passes rulemap[i + 1].n to pipapo_unmap() as the to_offset argument on every iteration, including the last one where i == m->field_count - 1. This reads one element past the end of the stack-allocated rulemap array (declared as rulemap[NFT_PIPAPO_MAX_FIELDS] with NFT_PIPAPO_MAX_FIELDS == 16). Although pipapo_unmap() returns early when is_last is true without using the to_offset value, the argument is evaluated at the call site before the function body executes, making this a genuine out-of-bounds stack read confirmed by KASAN: BUG: KASAN: stack-out-of-bounds in pipapo_drop+0x50c/0x57c [nf_tables] Read of size 4 at addr ffff8000810e71a4 This frame has 1 object: [32, 160) 'rulemap' The buggy address is at offset 164 -- exactly 4 bytes past the end of the rulemap array. Pass 0 instead of rulemap[i + 1].n on the last iteration to avoid the out-of-bounds read.
A stack out-of-bounds read vulnerability has been identified in the Linux kernel's netfilter component, specifically within the nft_set_pipapo functionality. This issue arises because the pipapo_drop() function incorrectly passes a value that references an element beyond the end of a stack-allocated array. The vulnerability has been confirmed using the Kernel Address Sanitizer (KASAN), which reported a stack-out-of-bounds read error. The problem occurs in versions of the Linux kernel where NFT_PIPAPO_MAX_FIELDS is set to 16.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched. The specific commit that addresses this issue is available in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0a55d62cdb628923d8a21724374a70c76ac7d19d | kernel.org | Patch |
| https://git.kernel.org/stable/c/1957e793196e7f8557374fd4eda53abcbb42e1c0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/324b749aa5b2d516ccfab933df9d3f56e7807f5f | kernel.org | Patch |
| https://git.kernel.org/stable/c/57fb87ca095d5127cd7a27583b8ec43dcf7c9e9e | kernel.org | Patch |
| https://git.kernel.org/stable/c/60c1d18781e37bfb96290b86510eb01c5fa24d75 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d6d8cd2db236a9dd13dbc2d05843b3445cc964b5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dfbdac719198778b581bc0dd055df2542edb8c62 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e047f6fbb975f685d6c9fcef95b3b7787a79b46d | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.6, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.167 >= 6.2, < 6.6.130 >= 6.7, < 6.12.78 >= 6.13, < 6.18.19 >= 6.19, < 6.19.9 7.0 rc1 7.0 rc2 7.0 rc3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 21, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | kernel.org |