CVE-2025-21826: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the concatenation, each field gets rounded up to 32-bits to calculate the pipapo rule width from pipapo_init(). The set key length provides the total size of the key aligned to 32-bits. Register-based arithmetics still allows for combining mismatching set key length and field length description, eg. set key length 10 and field description [ 5, 4 ] leading to pipapo width of 12.
Affected products
- Linux Linux Kernel: from 5.10.209, before 5.10.235 (fixed in 5.10.235); from 5.15.148, before 5.15.179 (fixed in 5.15.179); from 6.1.75, before 6.1.129 (fixed in 6.1.129); from 6.6.14, before 6.6.76 (fixed in 6.6.76); from 6.7.2, before 6.12.13 (fixed in 6.12.13); from 6.13, before 6.13.2 (fixed in 6.13.2)
Published 2025-03-06. Last modified 2026-07-30.