Review reviewCritical

CVE-2026-52999

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_osf_match_one() for each fingerprint checked. During TCP option parsing, nf_osf_match_one() advances the shared ctx->optp pointer. If a fingerprint perfectly matches, the function returns early without restoring ctx->optp to its initial state. If the user has configured NF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint. However, because ctx->optp...

CVSS
9.1
EPSS
0.51%
40.8% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.51%
Technical severityCVSS 9.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_osf_match_one() for each fingerprint checked. During TCP option parsing, nf_osf_match_one() advances the shared ctx->optp pointer. If a fingerprint perfectly matches, the function returns early without restoring ctx->optp to its initial state. If the user has configured NF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint. However, because ctx->optp...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b < 0145548346c4a30981a870a8ca00eac46ba27e85, >= 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b < 1c136f2c44a5913646bac85303612fd0825197a0, >= 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b < 1e19a07291bb8682c14c39a64725a3ae54ab8ccc, >= 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b < 32e50f92c7cf3f4eba29622179a5fcdc2aebab41, >= 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b < 70a3f31d25cf2ec9d4ddfa408120171ead955623, >= 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b < 21883587593d7c8bb519a79460a0b5bc5ffbdabd, >= 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b < edb78a142d2e5948e63647c0646aa7e7886935f0, >= 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b < f5ca450087c3baf3651055e7a6de92600f827af3, >= 0c1054e0e5fdef2369fb089e94def978bd209e1f, >= 8316b60582facd4068fb0916c4db2418c21b7174, >= 4.19.26 < 4.20, >= 4.20.13 < 4.21, >= 5.0, >= 4.20.13 < 5.0, >= 5.0.1 < 5.10.258, >= 5.11 < 5.15.209, >= 5.16 < 6.1.175, >= 6.2 < 6.6.141, >= 6.7 < 6.12.91, >= 6.13 < 6.18.33
Fixed versions
4.20, 5.0, 5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125
CVE-2026-52999 — Linux Linux, linux kernel | SECUFOCUS NOW