CVE-2025-21826
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-21826 is a vulnerability discovered in the Linux kernel's netfilter component, specifically in the nf_tables subsystem. The vulnerability was disclosed on March 6, 2025, affecting the field length description handling in the netfilter's pipapo rule width calculation. This security issue impacts various Linux distributions including Ubuntu, Debian, and Red Hat Enterprise Linux systems (Ubuntu Security, Debian Tracker, Red Hat CVE).

Technical details

The vulnerability exists in the way nftables handles field length descriptions for key field concatenation. The issue occurs when calculating the pipapo rule width from pipapoinit(), where each field gets rounded up to 32-bits. The set key length provides the total size of the key aligned to 32-bits, but register-based arithmetics allows for combining mismatching set key length and field length descriptions. For example, a set key length of 10 and field description [5, 4] can lead to a pipapo width of 12, creating a potential security risk (Kernel Git). The vulnerability has been assigned a CVSS v3.1 score of 5.5 (Moderate) with the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat CVE).

Impact

The vulnerability affects the availability of the system, as indicated by the CVSS metrics showing High impact on availability (A:H) while having no direct impact on confidentiality (C:N) or integrity (I:N). The local attack vector (AV:L) suggests that an attacker would need local access to exploit this vulnerability (Red Hat CVE).

Mitigation and workarounds

The vulnerability has been fixed in various Linux kernel versions. Debian has fixed the issue in version 6.1.129-1 for bookworm and 6.12.17-1 for sid/trixie releases. Ubuntu has marked this as a medium priority issue and is providing updates for affected systems. Red Hat Enterprise Linux 9 is affected and working on updates, while versions 6 and 8 are not affected (Debian Tracker, Ubuntu Security, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-39730HIGH7.5
  • Linux KernelLinux Kernel
  • linux-hwe-6.8
NoYesSep 07, 2025
CVE-2025-39732HIGH7
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesSep 07, 2025
CVE-2025-39726MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-ibm-6.8
NoYesSep 05, 2025
CVE-2025-39727N/AN/A
  • Linux KernelLinux Kernel
  • linux-oracle
NoYesSep 07, 2025
CVE-2025-39725N/AN/A
  • Linux KernelLinux Kernel
  • perf
NoYesSep 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management