CVE-2026-43024: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject immediate NF_QUEUE verdict nft_queue is always used from userspace nftables to deliver the NF_QUEUE verdict. Immediately emitting an NF_QUEUE verdict is never used by the userspace nft tools, so reject immediate NF_QUEUE verdicts. The arp family does not provide queue support, but such an immediate verdict is still reachable. Globally reject NF_QUEUE immediate verdicts to address this issue.

Affected products

  • Linux Linux Kernel: from 4.19.307, before 4.20 (fixed in 4.20); from 5.4.269, before 5.5 (fixed in 5.5); from 5.10.210, before 5.10.253 (fixed in 5.10.253); from 5.15.149, before 5.15.203 (fixed in 5.15.203); from 6.1.76, before 6.1.168 (fixed in 6.1.168); from 6.6.15, before 6.6.134 (fixed in 6.6.134); …

Published 2026-05-01. Last modified 2026-07-14.