In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_payload: fix mask build for partial field offload
nft_payload_offload_mask() builds the offload match mask for a payload expression that covers only part of a header field. For a partial IPv6 address match (field_len = 16, priv_len = 1) that shift is 1 << 120, which is undefined on the 32-bit int operand. It also trims only one word, so the remaining words stay 0xffffffff (and when priv_len is a multiple of 4 the trim is skipped entirely), leaving the mask covering more bytes than the rule matches.
UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20 shift exponent 120 is too large for 32-bit type 'int' ...
The match is byte-granular and struct nft_data is zero-initialised, so the correct mask is simply the first priv_len bytes set to 0xff. Set those bytes directly and drop the word/shift trimming; this removes the undefined shift and no longer over-masks the trailing bytes.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade bpftool6.12Upgrade kernel6.12-tools-debuginfoUpgrade python3-perf6.12-debuginfoUpgrade kernel6.12-debuginfoUpgrade perf6.12-debuginfoUpgrade kernel6.12-modules-extraUpgrade kernel6.12-tools-develUpgrade kernel6.12-modules-extra-commonUpgrade kernel6.12Upgrade perf6.12Upgrade kernel6.12-toolsUpgrade kernel-livepatch-6.12.103-127.188Upgrade python3-perf6.12Upgrade kernel6.12-develUpgrade kernel6.12-debuginfo-common-x86_64Upgrade kernel6.12-headersUpgrade kernel6.12-debuginfo-common-aarch64Upgrade bpftool6.12-debuginfo | Sep 1, 2026 | Aug 17, 2026 |
| Debian | — | Upgrade linux | Aug 26, 2026 | Aug 26, 2026 |
| Redhat_linux | — | No solution exists | Aug 19, 2026 | Aug 17, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 27, 2026 | Aug 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub