CVE-2012-2663: Netfilter Iptables

High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.

extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.

Affected products

  • Netfilter Iptables: up to and including 1.4.21

Published 2014-02-15. Last modified 2026-06-16.