Bug 2466994 (CVE-2026-43114) - CVE-2026-43114 kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry
Summary: CVE-2026-43114 kernel: netfilter: nft_set_pipapo_avx2: don't return non-match...
Keywords:
Status: NEW
Alias: CVE-2026-43114
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-06 10:02 UTC by OSIDB Bzimport
Modified: 2026-09-30 07:52 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:59723 0 None None None 2026-08-26 04:35:23 UTC
Red Hat Product Errata RHSA-2026:62568 0 None None None 2026-09-02 11:02:42 UTC
Red Hat Product Errata RHSA-2026:62638 0 None None None 2026-09-02 13:53:05 UTC
Red Hat Product Errata RHSA-2026:62639 0 None None None 2026-09-02 14:00:10 UTC
Red Hat Product Errata RHSA-2026:62640 0 None None None 2026-09-02 14:07:37 UTC
Red Hat Product Errata RHSA-2026:62641 0 None None None 2026-09-02 14:11:38 UTC
Red Hat Product Errata RHSA-2026:62642 0 None None None 2026-09-02 14:03:26 UTC
Red Hat Product Errata RHSA-2026:63093 0 None None None 2026-09-08 13:15:20 UTC
Red Hat Product Errata RHSA-2026:64767 0 None None None 2026-09-08 00:23:43 UTC
Red Hat Product Errata RHSA-2026:65712 0 None None None 2026-09-09 00:57:40 UTC
Red Hat Product Errata RHSA-2026:66351 0 None None None 2026-09-15 09:18:04 UTC
Red Hat Product Errata RHSA-2026:66370 0 None None None 2026-09-16 06:49:37 UTC
Red Hat Product Errata RHSA-2026:66376 0 None None None 2026-09-15 09:21:59 UTC
Red Hat Product Errata RHSA-2026:67721 0 None None None 2026-09-16 00:14:23 UTC
Red Hat Product Errata RHSA-2026:67723 0 None None None 2026-09-16 00:42:10 UTC

Description OSIDB Bzimport 2026-05-06 10:02:17 UTC
In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry

New test case fails unexpectedly when avx2 matching functions are used.

The test first loads a ranomly generated pipapo set
with 'ipv4 . port' key, i.e.  nft -f foo.

This works.  Then, it reloads the set after a flush:
(echo flush set t s; cat foo) | nft -f -

This is expected to work, because its the same set after all and it was
already loaded once.

But with avx2, this fails: nft reports a clashing element.

The reported clash is of following form:

    We successfully re-inserted
      a . b
      c . d

Then we try to insert a . d

avx2 finds the already existing a . d, which (due to 'flush set') is marked
as invalid in the new generation.  It skips the element and moves to next.

Due to incorrect masking, the skip-step finds the next matching
element *only considering the first field*,

i.e. we return the already reinserted "a . b", even though the
last field is different and the entry should not have been matched.

No such error is reported for the generic c implementation (no avx2) or when
the last field has to use the 'nft_pipapo_avx2_lookup_slow' fallback.

Bisection points to
7711f4bb4b36 ("netfilter: nft_set_pipapo: fix range overlap detection")
but that fix merely uncovers this bug.

Before this commit, the wrong element is returned, but erronously
reported as a full, identical duplicate.

The root-cause is too early return in the avx2 match functions.
When we process the last field, we should continue to process data
until the entire input size has been consumed to make sure no stale
bits remain in the map.

Comment 5 errata-xmlrpc 2026-08-26 04:35:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:59723 https://access.redhat.com/errata/RHSA-2026:59723

Comment 6 errata-xmlrpc 2026-09-02 11:02:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62568 https://access.redhat.com/errata/RHSA-2026:62568

Comment 7 errata-xmlrpc 2026-09-02 13:53:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:62638 https://access.redhat.com/errata/RHSA-2026:62638

Comment 8 errata-xmlrpc 2026-09-02 14:00:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:62639 https://access.redhat.com/errata/RHSA-2026:62639

Comment 9 errata-xmlrpc 2026-09-02 14:03:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:62642 https://access.redhat.com/errata/RHSA-2026:62642

Comment 10 errata-xmlrpc 2026-09-02 14:07:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:62640 https://access.redhat.com/errata/RHSA-2026:62640

Comment 11 errata-xmlrpc 2026-09-02 14:11:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62641 https://access.redhat.com/errata/RHSA-2026:62641

Comment 12 errata-xmlrpc 2026-09-08 00:23:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:64767 https://access.redhat.com/errata/RHSA-2026:64767

Comment 13 errata-xmlrpc 2026-09-08 13:15:18 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:63093 https://access.redhat.com/errata/RHSA-2026:63093

Comment 14 errata-xmlrpc 2026-09-09 00:57:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:65712 https://access.redhat.com/errata/RHSA-2026:65712

Comment 15 Jon Orris 2026-09-15 09:18:02 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.21

Via RHSA-2026:66351 https://access.redhat.com/errata/RHSA-2026:66351

Comment 16 Jon Orris 2026-09-15 09:21:58 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2026:66376 https://access.redhat.com/errata/RHSA-2026:66376

Comment 17 Jon Orris 2026-09-16 00:14:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:67721 https://access.redhat.com/errata/RHSA-2026:67721

Comment 18 Jon Orris 2026-09-16 00:42:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:67723 https://access.redhat.com/errata/RHSA-2026:67723

Comment 19 Jon Orris 2026-09-16 06:49:35 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.19

Via RHSA-2026:66370 https://access.redhat.com/errata/RHSA-2026:66370


Note You need to log in before you can comment on or make changes to this bug.