netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH

Summary

CVECVE-2026-74564
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 13:18:01 UTC
Updated2026-08-15 13:18:01 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the dsthash_ent structure which represents an entry in the hashtable. There is a union area which uses a different layout to express the rate match mode. Update .checkentry path to validate the XT_HASHLIMIT_RATE_MATCH mode flag is requested by two or more different rules that refer to the same hashtable. Otherwise, uninitialized access to the burst field in the union is possible. Reject the use of the XT_HASHLIMIT_RATE_MATCH mode flag if set on by revision less than 3 too.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected bea74641e3786d51dcf1175527cc1781420961c9 24683fea1f06bd3bd2707b99460e859bc6464c22 git Not specified
CNA Linux Linux affected bea74641e3786d51dcf1175527cc1781420961c9 32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0 git Not specified
CNA Linux Linux affected bea74641e3786d51dcf1175527cc1781420961c9 d186f77d18bdfb252d401ff992ca3001a6a65a0f git Not specified
CNA Linux Linux affected bea74641e3786d51dcf1175527cc1781420961c9 06a76334243ccd875a981aa8bb46c0f931ef1e3b git Not specified
CNA Linux Linux affected bea74641e3786d51dcf1175527cc1781420961c9 305b63e1402267459fdabb183af4527f6799eebf git Not specified
CNA Linux Linux affected 4.14 Not specified
CNA Linux Linux unaffected 4.14 semver Not specified
CNA Linux Linux unaffected 6.6.151 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.103 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.44 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.8 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc6 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/305b63e1402267459fdabb183af4527f6799eebf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/06a76334243ccd875a981aa8bb46c0f931ef1e3b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d186f77d18bdfb252d401ff992ca3001a6a65a0f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/24683fea1f06bd3bd2707b99460e859bc6464c22 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report