Description
In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_u32: reject invalid shift counts

u32_match_it() executes rule-supplied shift operands on a 32-bit
value. A malformed u32 rule can provide a shift count of 32 or more,
triggering an undefined shift out-of-bounds during packet evaluation.

Validate XT_U32_LEFTSH and XT_U32_RIGHTSH operands in
u32_mt_checkentry() and reject malformed rules before they reach the
packet path.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unsafe shift operations in the Linux kernel netfilter xt_u32 module allow a malformed u32 rule to provide a shift count of 32 or more. Executing such a shift causes an undefined out-of-bounds behavior during packet evaluation, which could enable an attacker to corrupt kernel data or trigger a crash, leading to loss of confidentiality, integrity or availability.

Affected Systems

All Linux kernel releases prior to the patch that implements lower‑bound checking of XT_U32_LEFTSH and XT_U32_RIGHTSH operands are affected. The vulnerability applies to every kernel that loads the xt_u32 module and processes packet filtering rules that may contain malformed shift counts.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network‑based; an adversary can craft a packet containing a malformed u32 rule with a shift count of 32 or more that, when processed by the xt_u32 module, triggers an undefined shift out‑of-bounds during packet evaluation. Exploitation would require that the victim system accepts and processes such a rule, potentially causing a kernel crash or compromising system integrity.

Generated by OpenCVE AI on August 22, 2026 at 05:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Linux kernel that includes the fixed validation of u32 shift operands.
  • Ensure the xt_u32 module is not loaded with deprecated or incomplete configurations by verifying module parameters and kernel config before deployment.
  • Actively monitor system logs for warnings or crashes related to netfilter packet processing, and consider rolling back to a stable kernel if the vulnerability cannot be remedied in a timely manner.

Generated by OpenCVE AI on August 22, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 00:15:00 +0000


Mon, 17 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-682

Mon, 17 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_u32: reject invalid shift counts u32_match_it() executes rule-supplied shift operands on a 32-bit value. A malformed u32 rule can provide a shift count of 32 or more, triggering an undefined shift out-of-bounds during packet evaluation. Validate XT_U32_LEFTSH and XT_U32_RIGHTSH operands in u32_mt_checkentry() and reject malformed rules before they reach the packet path.
Title netfilter: xt_u32: reject invalid shift counts
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:43:07.758Z

Reserved: 2026-08-09T03:40:39.921Z

Link: CVE-2026-72350

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:08.407

Modified: 2026-08-17T06:18:39.020

Link: CVE-2026-72350

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72350 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T05:30:17Z

Weaknesses
  • CWE-1335

    Incorrect Bitwise Shift of Integer

  • CWE-20

    Improper Input Validation

  • CWE-682

    Incorrect Calculation