CVE-2026-52921
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
08/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: ipset: stop hash:* range iteration at end<br />
<br />
The following hash set variants:<br />
<br />
hash:ip,mark<br />
hash:ip,port<br />
hash:ip,port,ip<br />
hash:ip,port,net<br />
<br />
iterate IPv4 ranges with a 32-bit iterator.<br />
<br />
The iterator must stop once the last address in the requested range has<br />
been processed. Advancing it once more can move the traversal state past<br />
the end of the request, so a later retry may continue from an unintended<br />
position.<br />
<br />
Handle the iterator increment explicitly at the end of the loop and stop<br />
once the upper bound has been processed. This keeps the existing retry<br />
behaviour intact for valid ranges while preventing traversal from<br />
continuing past the original boundary.
Impacto
Puntuación base 3.x
5.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.14.1 (incluyendo) | 5.10.258 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.209 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.175 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.142 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.92 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.34 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.11 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:4.14:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.14:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.14:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.14:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.14:rc8:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/02f75f041a93ea045834da89cd3234f4c1d749b4
- https://git.kernel.org/stable/c/0b530efb2cc9dbdddfd49d392e3a857f0d4ce8dc
- https://git.kernel.org/stable/c/0d3a282ab5f165fc207ff49ea5b6ad8f54616bd6
- https://git.kernel.org/stable/c/0d7b33ace701fe397e6e4de145f32e098178d901
- https://git.kernel.org/stable/c/383418c20e69f5761b6ec5238f599423f4fb77fb
- https://git.kernel.org/stable/c/952e988163c2ab9939c3db9f0f8e77af6a1bb436
- https://git.kernel.org/stable/c/be75218fadea22e59c8673db212f29c681bf45bb
- https://git.kernel.org/stable/c/c281e018af98df91827d65bec00f4956c00a1b02



