Linux Kernel Netfilter xt_multiport Range Encoding Validation Vulnerability

Vulnerability

A vulnerability in the Linux kernel's netfilter component, specifically within the xt_multiport module, has been addressed. The issue arose because the range encoding of port specifications was not properly validated, allowing malformed rules to disrupt normal processing. This vulnerability affected the rule interpretation by skipping past the last valid port element, potentially leading to incorrect behavior in network traffic filtering.

Impact

Exploitation of this vulnerability could result in malformed multiport v1 rules being accepted, which could disrupt the normal functioning of the netfilter framework by misinterpreting port ranges in traffic rules.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: Apr 25, 2026, 9:21 AM
Updated: Apr 25, 2026, 9:21 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.0
remediation
7.7
relevance
6.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.