« Volver al listado

CVE-2026-45873

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets

Userspace provides an optimized representation in case intervals are adjacent, where the end element is omitted.

The existing partial overlap detection logic skips anonymous set checks on start elements for this reason.

However, it is possible to add intervals that overlap to this anonymous where two start elements with the same, eg. A-B, A-C where C < B.

Restore the check on overlapping start elements to report an overlap.

Detalles técnicos trazas, registros y código del informe original
      start     end
	A        B
      start  end
        A     C

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-45873",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4aacf3d78424293e318c616016865380b37b9cc5",
              "lessThan": "7ca5813e1b21ef300e04593f47b073ef3217aac6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2bf1435fa19d2c58054391b3bba40d5510a5758c",
              "lessThan": "029e5f6a95e905b12d6bc20421be32a01e0eb311",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "318cb24a4c3fce8140afaf84e4d45fcb76fb280b",
              "lessThan": "f1381ce0a1dd013610985e1c4260908163a427df",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9e6978e2725a7d4b6cd23b2facd3f11422c0643",
              "lessThan": "f1535d56fc3f6c625b7e0559c006bd0318791bb1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9e6978e2725a7d4b6cd23b2facd3f11422c0643",
              "lessThan": "05feaf826390fd16f1deb89dd9412def3b2a280f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9e6978e2725a7d4b6cd23b2facd3f11422c0643",
              "lessThan": "dad14d22dff1a191612acb98facceb303d0524a2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9e6978e2725a7d4b6cd23b2facd3f11422c0643",
              "lessThan": "e6497e06a102870803a59570d75ed2c36d7e11b3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9e6978e2725a7d4b6cd23b2facd3f11422c0643",
              "lessThan": "4780ec142cbb24b794129d3080eee5cac2943ffc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7ab87a326f20c52ff4d9972052d085be951c704b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "181859bdfb9734aca449512fccaee4cacce64aed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.166",
              "lessThan": "5.10.252",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.91",
              "lessThan": "5.15.202",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.9",
              "lessThan": "6.1.165",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.316",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.262",
              "lessThan": "5.5",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/netfilter/nft_set_rbtree.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.252",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.202",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.165",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.128",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.75",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.14",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19.4",
              "versionType": "semver",
              "lessThanOrEqual": "6.19.*"
            },
            {
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/netfilter/nft_set_rbtree.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-05-27T14:17:00.780",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/029e5f6a95e905b12d6bc20421be32a01e0eb311",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/05feaf826390fd16f1deb89dd9412def3b2a280f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4780ec142cbb24b794129d3080eee5cac2943ffc",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7ca5813e1b21ef300e04593f47b073ef3217aac6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dad14d22dff1a191612acb98facceb303d0524a2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e6497e06a102870803a59570d75ed2c36d7e11b3",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f1381ce0a1dd013610985e1c4260908163a427df",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f1535d56fc3f6c625b7e0559c006bd0318791bb1",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_rbtree: check for partial overlaps in anonymous sets\n\nUserspace provides an optimized representation in case intervals are\nadjacent, where the end element is omitted.\n\nThe existing partial overlap detection logic skips anonymous set checks\non start elements for this reason.\n\nHowever, it is possible to add intervals that overlap to this anonymous\nwhere two start elements with the same, eg. A-B, A-C where C < B.\n\n      start     end\n\tA        B\n      start  end\n        A     C\n\nRestore the check on overlapping start elements to report an overlap."
    }
  ],
  "lastModified": "2026-06-25T21:06:04.977",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76EC9BF9-9775-4D90-B594-4C2AB71E1F86",
              "versionEndExcluding": "4.20",
              "versionStartIncluding": "4.19.316"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CE7F771-8144-4AEC-B6E3-5F4830BD8EB7",
              "versionEndExcluding": "5.5",
              "versionStartIncluding": "5.4.262"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9005873-27CF-4046-B8E1-755D96DF0EC3",
              "versionEndExcluding": "5.10.252",
              "versionStartIncluding": "5.10.166"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0179C040-8D00-4A6E-A1BA-9BE95B342A9F",
              "versionEndExcluding": "5.15.202",
              "versionStartIncluding": "5.15.91"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DAC5B1F-8281-4EF6-A25F-9D6A3BA9F93C",
              "versionEndExcluding": "6.1.165",
              "versionStartIncluding": "6.1.9"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6A74630-9345-4DA5-A7AF-7F3D9C192304",
              "versionEndExcluding": "6.6.128",
              "versionStartIncluding": "6.2.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCE16369-98ED-41CF-8995-DFDC10B288D2",
              "versionEndExcluding": "6.12.75",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF463CB7-1F58-4607-B847-77ED23E4B9B7",
              "versionEndExcluding": "6.18.14",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "672A3E79-EC03-479D-8503-361DFBDC8092",
              "versionEndExcluding": "6.19.4",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3ADCCCEE-143A-4B48-9B2A-0CB97BD385DE"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.2:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AB8D555-648E-4F2F-98BD-3E7F45BD12A8"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.2:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C64BDD9D-C663-4E75-AE06-356EDC392B82"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.2:rc8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26544390-88E4-41CA-98BF-7BB1E9D4E243"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}