CVE-2026-74564
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH<br />
<br />
The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the<br />
dsthash_ent structure which represents an entry in the hashtable. There<br />
is a union area which uses a different layout to express the rate match<br />
mode.<br />
<br />
Update .checkentry path to validate the XT_HASHLIMIT_RATE_MATCH mode<br />
flag is requested by two or more different rules that refer to the same<br />
hashtable. Otherwise, uninitialized access to the burst field in the<br />
union is possible.<br />
<br />
Reject the use of the XT_HASHLIMIT_RATE_MATCH mode flag if set on by<br />
revision less than 3 too.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/06a76334243ccd875a981aa8bb46c0f931ef1e3b
- https://git.kernel.org/stable/c/24683fea1f06bd3bd2707b99460e859bc6464c22
- https://git.kernel.org/stable/c/305b63e1402267459fdabb183af4527f6799eebf
- https://git.kernel.org/stable/c/32ec8d4aba2cf22e12bdc28df8c4bd833c195fc0
- https://git.kernel.org/stable/c/d186f77d18bdfb252d401ff992ca3001a6a65a0f



