{"id":"CVE-2026-74579","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74579","summary":"netfilter: nft_payload: fix mask build for partial field offload","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_payload: fix mask build for partial field offload\n\nnft_payload_offload_mask() builds the offload match mask for a payload\nexpression that covers only part of a header field.  For a partial IPv6\naddress match (field_len = 16, priv_len = 1) that shift is 1 << 120, which\nis undefined on the 32-bit int operand.  It also trims only one word, so\nthe remaining words stay 0xffffffff (and when priv_len is a multiple of 4\nthe trim is skipped entirely), leaving the mask covering more bytes than\nthe rule matches.\n\n  UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20\n  shift exponent 120 is too large for 32-bit type 'int'\n  ...\n\nThe match is byte-granular and struct nft_data is zero-initialised, so the\ncorrect mask is simply the first priv_len bytes set to 0xff. Set those\nbytes directly and drop the word/shift trimming; this removes the undefined\nshift and no longer over-masks the trailing bytes.","published":"2026-08-17T05:28:27.768Z","modified":"2026-08-21T03:30:40.338914459Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"5.10.265"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/16b553c46e347bc9de9946c4960654d5884a86de"},{"type":"WEB","url":"https://git.kernel.org/stable/c/363c3a84a946d53e5e121c9f47c7c2b7d228c46b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/39e88f28fb32bf02bd4b525c24c842c9cff5663d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3ee7b3f813b11f28cd6efdf7f24d64b5a7fd4dc7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/630295d5bba1d0e0f494cc459452eb0a0058c545"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8720df4504e0ed1781a702f65251bd47b3534d5e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a375d8ace807767f29f276b681b6324c74929b1d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b19b5d2e042c294e2cc1c908dc598f9d64015396"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74579.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74579"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-21T03:30:40.338914459Z"}}