CVE-2025-21826 - CVE House
Back to Database
Status published Unknown CVE-2025-21826

netfilter: nf_tables: reject mismatching sum of field_len with set key length

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the concatenation, each field gets rounded up to 32-bits to calculate the pipapo rule width from pipapo_init(). The set key length provides the total size of the key aligned to 32-bits. Register-based arithmetics still allows for combining mismatching set key length and field length description, eg. set key length 10 and field description [ 5, 4 ] leading to pipapo width of 12.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-21826

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
2d4c0798a1ef8db15b3277697ac2def4eda42312, 77be8c495a3f841e88b46508cc20d3d7d3289da3, 9cb084df01e198119de477ac691d682fb01e80f3, dc45bb00e66a33de1abb29e3d587880e1d4d9a7e, 3ce67e3793f48c1b9635beb9bb71116ca1e51b58, ff67e3e488090908dc015ba04d7407d8bd467f7e, 5.10.209, 5.15.148, 6.1.75, 6.6.14, 6.7.2, 6.8, 0, 5.10.235, 5.15.179, 6.1.129, 6.6.76, 6.12.13, 6.13.2, 6.14

Timeline

Official Publish: March 6th, 2025
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.