CVE-2026-43114General(linux / linux_kernel)

LOWCVSS 9.4 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4 . port' key, i.e. nft -f foo. This works. Then, it reloads the set after a flush: (echo flush set t s; cat foo) | nft -f - This is expected to work, because its the same set after all and it was already loaded once. But with avx2, this fails: nft reports a clashing element. The reported clash is of following form: We successfully re-inserted a . b c . d Then we try to insert a . d avx2 finds the already existing a . d, which (due to 'flush set') is marked as invalid in the new generation. It skips the element and moves to next. Due to incorrect masking, the skip-step finds the next matching element *only considering the first field*, i.e. we return the already reinserted "a . b", even though the last field is different and the entry should not have been matched. No such error is reported for the generic c implementation (no avx2) or when the last field has to use the 'nft_pipapo_avx2_lookup_slow' fallback. Bisection points to 7711f4bb4b36 ("netfilter: nft_set_pipapo: fix range overlap detection") but that fix merely uncovers this bug. Before this commit, the wrong element is returned, but erronously reported as a full, identical duplicate. The root-cause is too early return in the avx2 match functions. When we process the last field, we should continue to process data until the entire input size has been consumed to make sure no stale bits remain in the map.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-480

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-13)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-06: 1Mentions · 2026-05-13: 4Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-13: 305-0605-13
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Patch
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-134
General3Patch1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.4 CRITICAL · CVE-2026-43114 · 9.4 → 3.1 CVE: CVE-2026-43114 CVSS: 9.4 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Severity: CRITICAL Status: Critical advisory

    Post summary

    A critical advisory is issued for CVE-2026-43114 with a CVSS score of 9.4, but no PoC, exploit, active use, or patch information is disclosed.

    1000025
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    The test first loads a ranomly generated pipapo set with 'ipv4. port' key, i.e. nft -f foo. CVE: CVE-2026-43114 CVSS: 9.4 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists CVE-2026-43114 with its CVSS score and critical severity, but offers no details on exploitation, patches, or PoC.

    1000023
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE: CVE-2026-43114 CVSS: 9.4 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Severity: CRITICAL Status: Critical advisory In the Linux kernel, the following vulnerability has been resolved: netfilter: nftsetpipapoavx2: don't return non-matching entry on expiry…

    Post summary

    CVE-2026-43114 is a critical Linux kernel vulnerability (CVSS 9.4) that has been addressed; the text does not provide PoC, exploit details, or evidence of active exploitation.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43114-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The content is a URL link pointing to an advisory for CVE‑2026‑43114 but provides no additional details or actionable information within the text itself.

    0000023
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43114 Linux Kernel Netfilter AVX2 Pipapo Set Incorrect Element Matching on Expiry https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43114

    Post summary

    A new kernel vulnerability, CVE-2026-43114, involves incorrect element matching on expiry in the Netfilter AVX2 Pipapo set; however, no PoC, exploit code, or patch details are provided.

    0000048
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more