CVE-2026-43453
Published: May 8, 2026
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop() pipapo_drop() passes rulemap[i + 1].n to pipapo_unmap() as the to_offset argument on every iteration, including the last one where i == m->field_count - 1. This reads one element past the end of the stack-allocated rulemap array (declared as rulemap[NFT_PIPAPO_MAX_FIELDS] with NFT_PIPAPO_MAX_FIELDS == 16). Although pipapo_unmap() returns early when is_last is true without using the to_offset value, the argument is evaluated at the call site before the function body executes, making this a genuine out-of-bounds stack read confirmed by KASAN: BUG: KASAN: stack-out-of-bounds in pipapo_drop+0x50c/0x57c [nf_tables] Read of size 4 at addr ffff8000810e71a4 This frame has 1 object: [32, 160) 'rulemap' The buggy address is at offset 164 -- exactly 4 bytes past the end of the rulemap array. Pass 0 instead of rulemap[i + 1].n on the last iteration to avoid the out-of-bounds read.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 3c4287f62044a90e73a561aa05fc46e62da173da - < 1957e793196e7f8557374fd4eda53abcbb42e1c0affected 3c4287f62044a90e73a561aa05fc46e62da173da - < 57fb87ca095d5127cd7a27583b8ec43dcf7c9e9eaffected 3c4287f62044a90e73a561aa05fc46e62da173da - < 60c1d18781e37bfb96290b86510eb01c5fa24d75affected 3c4287f62044a90e73a561aa05fc46e62da173da - < 0a55d62cdb628923d8a21724374a70c76ac7d19daffected 3c4287f62044a90e73a561aa05fc46e62da173da - < dfbdac719198778b581bc0dd055df2542edb8c62+3 more versions |
Linux | Linux | affected 5.6unaffected 0 - < 5.6unaffected 5.10.253 - <= 5.10.*unaffected 5.15.203 - <= 5.15.*unaffected 6.1.167 - <= 6.1.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now