Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-45841— netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于nf_osf_match_one在OSF_WSS_MODULO分支计算ctx->window % f->wss.val时未检查f->wss.val为零,可能导致CAP_NET_ADMIN用户添加此类指纹后后续匹配TCP SYN除零导致内核崩溃。

AI Predicted 5.3 Difficulty: Trivial EPSS 0.13% · P3

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384< cb833bbc1b3c51e08652d3c86298307c07d3f2db affected
11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384< 26900306a5a2c3e4f75c643a064525526bb6e5f3 affected
11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384< 0694618cf3e9b120666e31f5f383a6e466d95a0d affected
11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384< 8def8fbd23f40e945febe913d04b731012ce0082 affected
11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384< c55940895245d8ef658ab381248a28755218d625 affected
11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384< fb965b1cfe92b28d28b5ebe3116b81dbef9f2d2f affected
11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384< 9a05e195618a6d474f2bcd5b6376d0ffc2f00366 affected
11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384< 2195574dc6d9017d32ac346987e12659f931d932 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45841

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO nf_osf_match_one() computes ctx->window % f->wss.val in the OSF_WSS_MODULO branch with no guard for f->wss.val == 0. A CAP_NET_ADMIN user can add such a fingerprint via nfnetlink; a subsequent matching TCP SYN divides by zero and panics the kernel. Reject the bogus fingerprint in nfnl_osf_add_callback() above the per-option for-loop. f->wss is per-fingerprint, not per-option, so the check must run regardless of f->opt_num (including 0). Also reject wss.wc >= OSF_WSS_MAX; nf_osf_match_one() already treats that as "should not happen". Crash: Oops: divide error: 0000 [#1] SMP KASAN NOPTI RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98) Call Trace: <IRQ> nf_osf_match (net/netfilter/nfnetlink_osf.c:220) xt_osf_match_packet (net/netfilter/xt_osf.c:32) ipt_do_table (net/ipv4/netfilter/ip_tables.c:348) nf_hook_slow (net/netfilter/core.c:622) ip_local_deliver (net/ipv4/ip_input.c:265) ip_rcv (include/linux/skbuff.h:1162) __netif_receive_skb_one_core (net/core/dev.c:6181) process_backlog (net/core/dev.c:6642) __napi_poll (net/core/dev.c:7710) net_rx_action (net/core/dev.c:7945) handle_softirqs (kernel/softirq.c:622)
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于nf_osf_match_one在OSF_WSS_MODULO分支计算ctx->window % f->wss.val时未检查f->wss.val为零,可能导致CAP_NET_ADMIN用户添加此类指纹后后续匹配TCP SYN除零导致内核崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 ~ cb833bbc1b3c51e08652d3c86298307c07d3f2db -
Linux Linux 2.6.31 -

II. Public POCs for CVE-2026-45841

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45841

登录查看更多情报信息。

Patches & Fixes for CVE-2026-45841 (7)

Same Patch Batch · Linux · 2026-05-27 · 275 CVEs total

CVE-2026-46039 9.8 CRITICAL rxgk: Fix potential integer overflow in length check
CVE-2026-45898 9.8 CRITICAL RDMA/iwcm: Fix workqueue list corruption by removing work_list
CVE-2026-45972 9.8 CRITICAL smb: client: fix potential UAF and double free in smb2_open_file()
CVE-2026-45988 9.8 CRITICAL rxrpc: Fix re-decryption of RESPONSE packets
CVE-2026-46043 9.1 CRITICAL RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
CVE-2026-45945 8.8 HIGH iommu/vt-d: Fix race condition during PASID entry replacement
CVE-2026-46056 8.8 HIGH Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
CVE-2025-71311 8.2 HIGH fs/ntfs3: Initialize new folios before use
CVE-2026-46037 8.2 HIGH ipv4: icmp: validate reply type before using icmp_pointers
CVE-2026-45843 8.2 HIGH slip: bound decode() reads against the compressed packet length
CVE-2026-46099 8.1 HIGH net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
CVE-2026-46010 8.1 HIGH rxrpc: Fix error handling in rxgk_extract_token()
CVE-2026-46076 7.9 HIGH KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-45910 7.8 HIGH RDMA/rxe: Fix race condition in QP timer handlers
CVE-2026-45931 7.8 HIGH accel/amdxdna: Hold mm structure across iommu_sva_unbind_device()
CVE-2026-45956 7.8 HIGH drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()
CVE-2026-46036 7.8 HIGH vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex
CVE-2026-46100 7.8 HIGH fs: afs: revert mmap_prepare() change
CVE-2026-45894 7.8 HIGH iommu/vt-d: Clear Present bit before tearing down PASID entry
CVE-2026-45933 7.8 HIGH bpf: Preserve id of register in sync_linked_regs()

Showing top 20 of 275 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-45841

No comments yet


Leave a comment