Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72252— netfilter: nft_set_pipapo: don't leak bad clone into future transaction

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 5.6版本存在安全漏洞,该漏洞源于netfilter nft_set_pipapo在内存分配失败时克隆的nft_pipapo_match进入错误状态,可能导致后续插入操作触发越界写入。

CVSS 7.8 · High EPSS 0.16% · P6

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux 3c4287f62044a90e73a561aa05fc46e62da173da< 0ab7b1802f63ca5b288ea59acb467830b83abd6b affected
3c4287f62044a90e73a561aa05fc46e62da173da< cc53703f48558896295f565cd4f5e956d21b7af4 affected
3c4287f62044a90e73a561aa05fc46e62da173da< 047e813324eac2ac60cddfb58bcdbd0144eadb09 affected
3c4287f62044a90e73a561aa05fc46e62da173da< 610e3b73efaec3dd81a95dcda2421ad7d9795bd0 affected
3c4287f62044a90e73a561aa05fc46e62da173da< 02b6b0e892aea582590671796fd6eff5b93ea93f affected
3c4287f62044a90e73a561aa05fc46e62da173da< e74f9680e1b64872a51cc7b5bda1edaaa08aa51f affected
3c4287f62044a90e73a561aa05fc46e62da173da< 47e65eff50691f0a5b79d325e28d83ec1da43bcf affected
5.6 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72252

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
netfilter: nft_set_pipapo: don't leak bad clone into future transaction
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: don't leak bad clone into future transaction On memory allocation failure the cloned nft_pipapo_match can enter a bad state: - some fields can have their lookup tables resized while others did not - bits might have been toggled - scratch map can be undersized which also means m->bsize_max can be lower than what is required This means that the next insertion in the same batch can trigger out-of-bounds writes. Furthermore, a failure in the first can result in the bad clone to leak into the next transaction because the abort callback is never executed in this case (the upper layer saw an error and no attempt to allocate a transactional request was made). Record a state for the nft_pipapo_match structure: - NEW (pristine clone) - MOD (modified clone with good state) - ERR (potentially bogus content) Then make it so that deletes and insertions fail when the clone entered ERR state. In case the very first insert attempt results in an error, free the clone right away.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 5.6版本存在安全漏洞,该漏洞源于netfilter nft_set_pipapo在内存分配失败时克隆的nft_pipapo_match进入错误状态,可能导致后续插入操作触发越界写入。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 3c4287f62044a90e73a561aa05fc46e62da173da ~ 0ab7b1802f63ca5b288ea59acb467830b83abd6b -
Linux Linux 5.6 -

II. Public POCs for CVE-2026-72252

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72252

登录查看更多情报信息。

Patches & Fixes for CVE-2026-72252 (6)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-74376 9.8 CRITICAL md/raid10: reset read_slot when reusing r10bio for discard
CVE-2026-74433 9.8 CRITICAL rxrpc: Fix UAF in rxgk_issue_challenge()
CVE-2026-74434 9.8 CRITICAL rxrpc: Don't move a peeked OOB message onto the pending queue
CVE-2026-72191 9.8 CRITICAL ntfs3: validate split-point offset in indx_insert_into_buffer
CVE-2026-72299 9.8 CRITICAL tipc: restrict socket queue dumps in enqueue tracepoints
CVE-2026-72398 9.8 CRITICAL sctp: add INIT verification after cookie unpacking
CVE-2026-74384 9.8 CRITICAL nvme-multipath: fix flex array size in struct nvme_ns_head
CVE-2026-72442 9.8 CRITICAL netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
CVE-2026-74436 9.8 CRITICAL rxrpc: serialize kernel accept preallocation with socket teardown
CVE-2026-74545 9.8 CRITICAL rtase: fix double free of multi-frag skb on DMA map failure
CVE-2026-72046 9.8 CRITICAL gve: fix header buffer corruption with header-split and HW-GRO
CVE-2026-72473 9.8 CRITICAL xprtrdma: Decouple req recycling from RPC completion

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72252

No comments yet


Leave a comment