Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-21826— netfilter: nf_tables: reject mismatching sum of field_len with set key length

CVSS 7.8 · High EPSS 0.20% · P10

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 22

VendorProductVersion RangeStatus
LinuxLinux2d4c0798a1ef8db15b3277697ac2def4eda42312< 6b467c8feac759f4c5c86d708beca2aa2b29584faffected
77be8c495a3f841e88b46508cc20d3d7d3289da3< 5083a7ae45003456c253e981b30a43f71230b4a3affected
9cb084df01e198119de477ac691d682fb01e80f3< 2ac254343d3cf228ae0738b2615fedf85d000752affected
dc45bb00e66a33de1abb29e3d587880e1d4d9a7e< 82e491e085719068179ff6a5466b7387cc4bbf32affected
3ce67e3793f48c1b9635beb9bb71116ca1e51b58< 49b7182b97bafbd5645414aff054b4a65d05823daffected
3ce67e3793f48c1b9635beb9bb71116ca1e51b58< ab50d0eff4a939d20c37721fd9766347efcdb6f6affected
3ce67e3793f48c1b9635beb9bb71116ca1e51b58< 1b9335a8000fb70742f7db10af314104b6ace220affected
ff67e3e488090908dc015ba04d7407d8bd467f7eaffected
… +14 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-21826

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: nf_tables: reject mismatching sum of field_len with set key length
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the concatenation, each field gets rounded up to 32-bits to calculate the pipapo rule width from pipapo_init(). The set key length provides the total size of the key aligned to 32-bits. Register-based arithmetics still allows for combining mismatching set key length and field length description, eg. set key length 10 and field description [ 5, 4 ] leading to pipapo width of 12.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于nf_tables拒绝字段长度与集合密钥长度不匹配的情况。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 2d4c0798a1ef8db15b3277697ac2def4eda42312 ~ 6b467c8feac759f4c5c86d708beca2aa2b29584f -
LinuxLinux 6.8 -

II. Public POCs for CVE-2025-21826

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21826

登录查看更多情报信息。

Patches & Fixes for CVE-2025-21826 (5)

Other References for CVE-2025-21826 (1)

Same Patch Batch · Linux · 2025-03-06 · 46 CVEs total

CVE-2025-218299.8 CRITICALRDMA/rxe: Fix the warning "__rxe_cleanup+0x12c/0x170 [rdma_rxe]"
CVE-2025-218288.8 HIGHwifi: mac80211: don't flush non-uploaded STAs
CVE-2025-218257.8 HIGHbpf: Cancel the running bpf_timer through kworker for PREEMPT_RT
CVE-2024-580707.8 HIGHbpf: bpf_local_storage: Always use bpf_mem_alloc in PREEMPT_RT
CVE-2025-218327.8 HIGHblock: don't revert iter for -EIOCBQUEUED
CVE-2024-580837.8 HIGHKVM: Explicitly verify target vCPU is online in kvm_get_vcpu()
CVE-2024-580697.8 HIGHrtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read
CVE-2024-580867.8 HIGHdrm/v3d: Stop active perfmon if it is being destroyed
CVE-2024-580607.8 HIGHbpf: Reject struct_ops registration that uses module ptr and the module btf_id is missing
CVE-2024-580757.8 HIGHcrypto: tegra - do not transfer req when tegra init fails
CVE-2025-218277.8 HIGHBluetooth: btusb: mediatek: Add locks for usb_driver_claim_interface()
CVE-2024-580797.8 HIGHmedia: uvcvideo: Fix crash during unbind if gpio unit is in use
CVE-2024-580537.5 HIGHrxrpc: Fix handling of received connection abort
CVE-2025-218307.3 HIGHlandlock: Handle weird files
CVE-2024-58066clk: mmp: pxa1908-apbcp: Fix a NULL vs IS_ERR() check
CVE-2024-58064wifi: cfg80211: tests: Fix potential NULL dereference in test_cfg80211_parse_colocated_ap(
CVE-2024-58061wifi: mac80211: prohibit deactivating all links
CVE-2024-58063wifi: rtlwifi: fix memory leaks and invalid access at probe error path
CVE-2024-58065clk: mmp: pxa1908-apbc: Fix NULL vs IS_ERR() check
CVE-2024-58062wifi: iwlwifi: mvm: avoid NULL pointer dereference

Showing top 20 of 46 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-21826

No comments yet


Leave a comment