CVE-2025-38162

netfilter: nft_set_pipapo: prevent overflow in lookup table allocation

References

Notes

 carnil> Introduced in 3c4287f62044 ("nf_tables: Add set type for arbitrary
 carnil> concatenation of ranges"). Vulnerable versions: 5.6.

Bugs

Status

Branch Status
upstream released (6.16-rc1) [4c5c6aa9967dbe55bd017bb509885928d0f31206]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.15-upstream-stable released (6.15.3) [43fe1181f738295624696ae9ff611790edb65b5e]
6.12-upstream-stable released (6.12.34) [c1360ac8156c0a3f2385baef91d8d26fd9d39701]
6.6-upstream-stable needed
6.1-upstream-stable needed
5.10-upstream-stable needed
sid released (6.12.35-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security needed
5.10-bullseye-security needed