Review reviewHigh

CVE-2026-43329

Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload actions, 2 for each ethernet address) * SNAT (4 payload actions) * DNAT (4 payload actions) * Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing) for QinQ. * Redirect (1 action) Which makes 17, while the maximum is 16. But act_ct supports for tunnels actions too. Note that payload action operates at 32-bit word level, so mangling an IPv6 addres...

CVSS
7.8
EPSS
0.14%
3.88% percentile
CISA KEV
Not listed
Published
2026.05.08
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.14%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum number of flowtable hardware offload actions in IPv6 is: * ethernet mangling (4 payload actions, 2 for each ethernet address) * SNAT (4 payload actions) * DNAT (4 payload actions) * Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing) for QinQ. * Redirect (1 action) Which makes 17, while the maximum is 16. But act_ct supports for tunnels actions too. Note that payload action operates at 32-bit word level, so mangling an IPv6 addres...

Affected product and versions

Product
Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
Affected versions
>= c29f74e0df7a02b8303bcdce93a7c0132d62577a < ead66c77303f760f6c30be96e2e20d5a77cef614, >= c29f74e0df7a02b8303bcdce93a7c0132d62577a < fe9018d3e94329f1951b00805a8640bc06f56ead, >= c29f74e0df7a02b8303bcdce93a7c0132d62577a < 5382bb03e9c33b089d60788478b922a2dca284cc, >= c29f74e0df7a02b8303bcdce93a7c0132d62577a < 57c78bd2e2dd08897acd35b2bf8bcef322e36f5e, >= c29f74e0df7a02b8303bcdce93a7c0132d62577a < 504c9456699dcf4d15195ef34a0fa94a80bfc877, >= c29f74e0df7a02b8303bcdce93a7c0132d62577a < 879959a7a2be814dd57568655eafa3d8f4d0309e, >= c29f74e0df7a02b8303bcdce93a7c0132d62577a < 76522fcdbc3a02b568f5d957f7e66fc194abb893, >= 5.5, >= 5.5 < 5.15.203, >= 5.16 < 6.1.168, >= 6.2 < 6.6.134, >= 6.7 < 6.12.81, >= 6.13 < 6.18.22, >= 6.19 < 6.19.12, 7.0
Fixed versions
5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, 6.19.12

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-770
CVE-2026-43329 — Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support | SECUFOCUS NOW