PT-2025-9967 · Linux+8 · Linux Kernel+8

Noam Rathaus

·

Published

2025-01-30

·

Updated

2026-04-20

·

CVE-2025-21826

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A resolved issue in the Linux kernel involves a mismatch between the sum of field lengths and the set key length in the netfilter nf tables component. The field length description provides the length of each separated key field, which is rounded up to 32-bits to calculate the pipapo rule width. However, register-based arithmetics can still combine mismatching set key lengths and field length descriptions, potentially leading to incorrect pipapo widths.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:20095
ALSA-2025:20518
BDU:2025-12280
CVE-2025-21826
DLA-4102-1
DLA-4178-1
INFSA-2025_20518
OESA-2025-1446
OESA-2025-1450
RHSA-2025:20095
RHSA-2025:20518
RHSA-2025_20518
USN-7510-1
USN-7510-2
USN-7510-3
USN-7510-4
USN-7510-5
USN-7510-6
USN-7510-7
USN-7510-8
USN-7511-1
USN-7511-2
USN-7511-3
USN-7512-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7593-1
USN-7602-1
USN-7651-1
USN-7651-2
USN-7651-3
USN-7651-4
USN-7651-5
USN-7651-6
USN-7652-1
USN-7653-1
USN-7737-1

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Ubuntu