Linux Kernel Netfilter nf_set_pipapo_avx2 Initial Map Fill Vulnerability

Vulnerability

A vulnerability in the Linux kernel's netfilter component, specifically in the nf_set_pipapo_avx2 function, has been addressed. The issue arose when the first field did not completely cover the initial map, leading to a leakage of uninitialized bits into the subsequent match round map. Although an early fix was applied, it only corrected the generic C implementation. A follow-up patch has been introduced to nft_concat_range.sh to add a test case for this scenario.

Impact

Exploitation of this vulnerability could result in unintended data leakage between match rounds, potentially leading to incorrect processing of netfilter rules.

Added: Jul 3, 2025, 10:59 AM
Updated: Jul 3, 2025, 10:59 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.