CVE-2026-52999
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
In nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once and passed by reference to nf_osf_match_one() for each fingerprint checked. During TCP option parsing, nf_osf_match_one() advances the shared ctx->optp pointer.
If a fingerprint perfectly matches, the function returns early without restoring ctx->optp to its initial state. If the user has configured NF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint.
Leer descripción completaMostrar menos
However, because ctx->optp was not restored, the next call to nf_osf_match_one() starts parsing from the end of the options buffer. This causes subsequent matches to read garbage data and fail immediately, making it impossible to log more than one match or logging incorrect matches.
Instead of using a shared ctx->optp pointer, pass the context as a constant pointer and use a local pointer (optp) for TCP option traversal. This makes nf_osf_match_one() strictly stateless from the caller's perspective, ensuring every fingerprint check starts at the correct option offset.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.82%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto secundario
T1005Data from Local Systemcollection60 %
Vulnerabilidad de lectura fuera de límites (CWE-125) en kernel Linux accesible remotamente sin autenticación (AV:N/PR:N/UI:N). El impacto es DoS por lectura de datos y potencial información disclosure.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-125
Referencias
- https://git.kernel.org/stable/c/0145548346c4a30981a870a8ca00eac46ba27e85
- https://git.kernel.org/stable/c/1c136f2c44a5913646bac85303612fd0825197a0
- https://git.kernel.org/stable/c/1e19a07291bb8682c14c39a64725a3ae54ab8ccc
- https://git.kernel.org/stable/c/21883587593d7c8bb519a79460a0b5bc5ffbdabd
- https://git.kernel.org/stable/c/32e50f92c7cf3f4eba29622179a5fcdc2aebab41
- https://git.kernel.org/stable/c/70a3f31d25cf2ec9d4ddfa408120171ead955623
- https://git.kernel.org/stable/c/edb78a142d2e5948e63647c0646aa7e7886935f0
- https://git.kernel.org/stable/c/f5ca450087c3baf3651055e7a6de92600f827af3
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-52999",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b",
"lessThan": "0145548346c4a30981a870a8ca00eac46ba27e85",
"versionType": "git"
},
{
"status": "affected",
"version": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b",
"lessThan": "1c136f2c44a5913646bac85303612fd0825197a0",
"versionType": "git"
},
{
"status": "affected",
"version": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b",
"lessThan": "1e19a07291bb8682c14c39a64725a3ae54ab8ccc",
"versionType": "git"
},
{
"status": "affected",
"version": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b",
"lessThan": "32e50f92c7cf3f4eba29622179a5fcdc2aebab41",
"versionType": "git"
},
{
"status": "affected",
"version": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b",
"lessThan": "70a3f31d25cf2ec9d4ddfa408120171ead955623",
"versionType": "git"
},
{
"status": "affected",
"version": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b",
"lessThan": "21883587593d7c8bb519a79460a0b5bc5ffbdabd",
"versionType": "git"
},
{
"status": "affected",
"version": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b",
"lessThan": "edb78a142d2e5948e63647c0646aa7e7886935f0",
"versionType": "git"
},
{
"status": "affected",
"version": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b",
"lessThan": "f5ca450087c3baf3651055e7a6de92600f827af3",
"versionType": "git"
},
{
"status": "affected",
"version": "0c1054e0e5fdef2369fb089e94def978bd209e1f",
"versionType": "git"
},
{
"status": "affected",
"version": "8316b60582facd4068fb0916c4db2418c21b7174",
"versionType": "git"
},
{
"status": "affected",
"version": "4.19.26",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.20.13",
"lessThan": "4.21",
"versionType": "semver"
}
],
"programFiles": [
"net/netfilter/nfnetlink_osf.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.175",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.141",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.91",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.33",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.10",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/netfilter/nfnetlink_osf.c"
],
"defaultStatus": "affected"
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-06-24T17:17:10.913",
"references": [
{
"url": "https://git.kernel.org/stable/c/0145548346c4a30981a870a8ca00eac46ba27e85",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1c136f2c44a5913646bac85303612fd0825197a0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1e19a07291bb8682c14c39a64725a3ae54ab8ccc",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/21883587593d7c8bb519a79460a0b5bc5ffbdabd",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/32e50f92c7cf3f4eba29622179a5fcdc2aebab41",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/70a3f31d25cf2ec9d4ddfa408120171ead955623",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/edb78a142d2e5948e63647c0646aa7e7886935f0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f5ca450087c3baf3651055e7a6de92600f827af3",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix out-of-bounds read on option matching\n\nIn nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once\nand passed by reference to nf_osf_match_one() for each fingerprint\nchecked. During TCP option parsing, nf_osf_match_one() advances the\nshared ctx->optp pointer.\n\nIf a fingerprint perfectly matches, the function returns early without\nrestoring ctx->optp to its initial state. If the user has configured\nNF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint.\nHowever, because ctx->optp was not restored, the next call to\nnf_osf_match_one() starts parsing from the end of the options buffer.\nThis causes subsequent matches to read garbage data and fail\nimmediately, making it impossible to log more than one match or logging\nincorrect matches.\n\nInstead of using a shared ctx->optp pointer, pass the context as a\nconstant pointer and use a local pointer (optp) for TCP option\ntraversal. This makes nf_osf_match_one() strictly stateless from the\ncaller's perspective, ensuring every fingerprint check starts at the\ncorrect option offset."
}
],
"lastModified": "2026-09-08T09:18:12.990",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93062AA3-504F-48D6-A3CD-387C194809F6",
"versionEndExcluding": "4.20",
"versionStartIncluding": "4.19.26"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DAAFF5FD-7741-414F-8AEB-590CCD42FBBF",
"versionEndExcluding": "5.0",
"versionStartIncluding": "4.20.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "207F231A-355F-420A-8F04-8D692D978A01",
"versionEndExcluding": "5.10.258",
"versionStartIncluding": "5.0.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "919C10A9-7951-4A74-BADD-C135A0A8D8B4",
"versionEndExcluding": "5.15.209",
"versionStartIncluding": "5.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "92385813-D91D-480D-83A1-F423D2CBB2BA",
"versionEndExcluding": "6.1.175",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97A9FFFA-22BB-4D5C-9790-5A2286E392F7",
"versionEndExcluding": "6.6.141",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C918746B-DE6F-448F-A93E-A04C5481688D",
"versionEndExcluding": "6.12.91",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96D99E49-380D-43AB-BDBA-25C3AD018A9C",
"versionEndExcluding": "6.18.33",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A13475D2-59BF-4716-94B5-7C1D239A2CF4",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D0FE595-0CFE-4491-808B-CEF691CE7B0A"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.0:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C3430640-AC87-44BF-ABF5-09E0A97E3758"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.0:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDF49B77-4688-4908-9239-89B729456D22"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.0:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77F342FB-3D7B-4EAE-BF8B-57B7B860BAFD"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.0:rc8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47D61679-6515-4E18-83C7-A71982CCD83C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}