LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-52999

linux · linux kernel

Published
CVSS9.1
Severitycritical
WeaknessCWE-125
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_osf_match_one() for each fingerprint checked. During TCP option parsing, nf_osf_match_one() advances the shared ctx->optp pointer. If a fingerprint perfectly matches, the function returns early without restoring ctx->optp to its initial state. If the user has configured NF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint. However, because ctx->optp was not restored, the next call to nf_osf_match_one() starts parsing from the end of the options buf

References

← Back to the CVE Tracker

Our coverage of CVE-2026-52999

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-52999.