CVE-2026-74579
CVE CVE-2026-74579EUVD EUVD-2026-60050Published 2026-08-17T05:28:27.000ZLast changed 2026-08-19T16:39:16.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial field offload nft_payload_offload_mask() builds the offload match mask for a payload expression that covers only part of a header field. For a partial IPv6 address match (field_len = 16, priv_len = 1) that shift is 1 << 120, which is undefined on the 32-bit int operand. It also trims only one word, so the remaining words stay 0xffffffff (and when priv_len is a multiple of 4 the trim is skipped entirely), leaving the mask covering more bytes than the rule matches. UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20 shift exponent 120 is too large for 32-bit type 'int' ... The match is byte-granular and struct nft_data is zero-initialised, so the correct mask is simply the first priv_len bytes set to 0xff. Set those bytes directly and drop the word/shift trimming; this removes the undefined shift and no longer over-masks the trailing bytes.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 5c2b4b4f9fa5b765b927e361e3d310bcb5773015; a5d45bc0dc50f9dd83703510e9804d813a9cac32 <363c3a84a946d53e5e121c9f47c7c2b7d228c46b; a5d45bc0dc50f9dd83703510e9804d813a9cac32 <a375d8ace807767f29f276b681b6324c74929b1d; a5d45bc0dc50f9dd83703510e9804d813a9cac32 <39e88f28fb32bf02bd4b525c24c842c9cff5663d; patch: 6.6.151; patch: 6.12.103; a5d45bc0dc50f9dd83703510e9804d813a9cac32 <b19b5d2e042c294e2cc1c908dc598f9d64015396; patch: 7.1.8; patch: 5.10.265; 5.9.14 <5.10; patch: 7.2; a5d45bc0dc50f9dd83703510e9804d813a9cac32 <16b553c46e347bc9de9946c4960654d5884a86de; a5d45bc0dc50f9dd83703510e9804d813a9cac32 <3ee7b3f813b11f28cd6efdf7f24d64b5a7fd4dc7; patch: 0; patch: 6.1.183; a5d45bc0dc50f9dd83703510e9804d813a9cac32 <630295d5bba1d0e0f494cc459452eb0a0058c545; patch: 5.15.216; patch: 6.18.44; 5.10; a5d45bc0dc50f9dd83703510e9804d813a9cac32 <8720df4504e0ed1781a702f65251bd47b3534d5e
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.