PT-2026-38980 · Linux+3 · Linux Kernel+3

CVE-2026-43329

·

Published

2026-05-08

·

Updated

2026-08-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the netfilter flowtable component where the system fails to strictly check for the maximum number of supported actions. In IPv6 setups, the required number of hardware offload actions—including ethernet mangling, SNAT, DNAT, Double VLAN, and Redirect—can reach 17, exceeding the previous limit of 16. This is further complicated by act ct support for tunnel actions and the fact that payload actions operate at a 32-bit word level, requiring four actions to mangle an IPv6 address.
Recommendations Update the Linux kernel to a version where the flow action entry next() function is updated to strictly check for the maximum number of supported actions and where the maximum number of actions per flow has been increased from 16 to 24.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:23329
ALSA-2026:26427
ALSA-2026:26428
ALSA-2026:30848
CVE-2026-43329
OPENSUSE-SU-2026:20826-1
RHSA-2026:23329
RHSA-2026:26427
RHSA-2026:26428
RHSA-2026:27713
RHSA-2026:33215
RHSA-2026:33899
RHSA-2026:33900
RHSA-2026:34094
RHSA-2026:34095
RHSA-2026:35863
RHSA-2026:35896
SUSE-SU-2026:2111-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2195-1
SUSE-SU-2026:2202-1
SUSE-SU-2026:2215-1
SUSE-SU-2026:2216-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8665-1
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu