Linux Kernel Netfilter Vulnerability in Rate Matching Functionality
CVE-2026-74564
What is CVE-2026-74564?
A vulnerability has been identified in the Linux kernel's netfilter module, specifically concerning the XT_HASHLIMIT_RATE_MATCH flag. This flag alters the behavior of the dsthash_ent structure, affecting hashtable entries. When improperly validated, there is a risk of uninitialized access to the burst field within the union, which may lead to unintended behavior. To mitigate this risk, it is essential to ensure that the XT_HASHLIMIT_RATE_MATCH mode flag is only used when requested by two or more rules associated with the same hashtable. Additionally, support for this flag should be rejected if it refers to kernel revisions prior to revision 3.
Affected Version(s)
Linux bea74641e3786d51dcf1175527cc1781420961c9 < 24683fea1f06bd3bd2707b99460e859bc6464c22
Linux bea74641e3786d51dcf1175527cc1781420961c9 < 32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0
Linux bea74641e3786d51dcf1175527cc1781420961c9